Skip to main content

Internet Explorer users, be warned, a critical XSS bug is lurking in the shadows

microsoft browser loss internet explorer
Image used with permission by copyright holder
As if smears of past vulnerabilities and bugs weren’t enough to tarnish Internet Explorer’s reputation, a new security hole has been made public before Microsoft can plug it. This time, the discovery is quite clearly not a “gotcha” moment or the result of a rival holding a grudge.

David Leo from British security consultancy firm Deusen made the vexing disclosure, stressing there’s no universal fix available or patch downloadable. Tested on Windows 7 and 8.1 computers with IE’s version 11, the glitch allows cyber-aggressors to essentially hijack your browser.

Once a cross-site scripting (XSS) attack is remotely launched, the entire appearance of any given website can be manipulated at the hacker’s will in a matter of seconds. To illustrate the cataclysmic prospective effects of the malfunction, David Leo needs ten seconds and your approval here to plaster a “Hacked by Deusen” message on Daily Mail’s webpage.

Obviously, the publication’s actual site isn’t “hacked,” but if it’s so easy to make it look that way, think of what else a cyber-criminal could feed you. They could deceive you into handing them personal info, passwords, bank account numbers, you name it, simply by taking over trusted portals.

And the worst thing about it is you’re not even safe behind SSL encryptions. You know, addresses that start with “https.” Yup, those can be cracked too, due to the browser flaw allowing complete bypass of Same Origin Policy (SOP).

Don’t ask us to explain how the universal XSS bug came to be, we just know it’s bad. Really, really bad, and there’s no way to avoid it other than stop using Internet Explorer at once. In theory, invasions of privacy of this nature shouldn’t be possible in a pre-11 IE. But better safe than sorry, and better on Chrome or Firefox than IE.

For what it’s worth, Microsoft acknowledged the security snag without making a fuss, and confirmed work on an “update” while stating it’s not “aware of this vulnerability being actively exploited.” Whew, good thing Internet Explorer is going away.

Editors' Recommendations

Adrian Diaconescu
Former Digital Trends Contributor
Adrian is a mobile aficionado since the days of the Nokia 3310, and a PC enthusiast since Windows 98. Later, he discovered…
In a year, we’ll finally be able to say goodbye to Internet Explorer for good
microsoft issues emergency windows patch internet explorer 6 768x768

It's official -- the end of Internet Explorer is on the horizon. Microsoft confirmed what most of us already expected in a blog post released today. The company made the announcement over a year in advance. Starting on June 15, 2022, Internet Explorer will be retired and no longer supported on most versions of Windows 10. However, the legacy of IE11 lives on in Microsoft Edge.

While the vast majority of Windows 10 versions will no longer support IE11, Microsoft said that it won't be retired from all of them. This change will affect devices running Windows 10 version 20H2 and later, on both SKUs and IoT units. This means that most people are soon going to see the official retirement of Internet Explorer.

Read more
Internet Explorer zero-day exploit makes files vulnerable to hacks on Windows PCs
Windows 10 Surface Pro 4 stock photo

There were already a number of reasons to not use Internet Explorer. But if you needed another one, here it is.

According to ZDNet, a security researcher named John Page has published evidence of an Internet Explorer zero-day exploit that renders Windows PCs vulnerable to having their files stolen by hackers.

Read more
Microsoft security chief outlines perils of continuing to use Internet Explorer
Laptop running Internet Explorer.

If you’ve found yourself using Internet Explorer in the past decade, the chances are that you’ve had others suggest that you move to a more efficient browser such as Chrome or Firefox. Security expert Chris Jackson is also urging individuals to stop using Internet Explorer, but what makes his stance interesting is that he currently holds the position as Microsoft’s Worldwide Lead for Cybersecurity — that’s right, not even the folks at Microsoft want to see you opening Internet Explorer anymore.

Microsoft’s Security Lead isn’t suggesting that you drop Microsoft products and head for the hills. Instead, he specifically notes that Microsoft’s web browser of the past, Internet Explorer, has had its day. Jackson doesn’t even recommend a new solution for users looking to move off of Internet Explorer; while we are sure the team at Microsoft would like you to pick up Edge, he notes that he’s “not here to enforce any browser on anyone” and that “you should choose the one that best meets your needs.”

Read more