Skip to main content
  1. Home
  2. Computing
  3. News

Microsoft misses another Edge-related 90-day security disclosure deadline

Add as a preferred source on Google

Google’s Project Zero team released a report identifying another security flaw in Microsoft Edge. The team traditionally provides 90 days for developers to fix the uncovered issue(s) and exposes said issue(s) if they are not resolved within that timeframe. That means Microsoft didn’t respond to the team’s initial bug report, thus Project Zero is now coming forward with its findings. 

But Microsoft isn’t simply ignoring the report. The company deems the issue as “important” rather than “critical” because hackers can’t remotely take advantage of the Microsoft Edge security hole. Instead, they must execute code locally on the target PC using a normal privilege level. But the researcher who discovered the vulnerability deems it as “high severity” given it’s still easy to exploit despite the need for local device access. 

Recommended Videos

As for the actual problem, it provides hackers with administrator privileges on the target PC. That essentially means they can do anything on the device: Install programs, delete files, and so on. Getting administrator privileges through the vulnerability starts with the way a “hard-linked” file receives a security descriptor and is moved to a new destination. Once in the new folder, Windows 10 changes the file’s security descriptor to match the security settings of the current folder. 

That said, if the hard-linked file was originally set to read-only, the flaw allows anyone on the network to edit that file after it’s moved to the new directory. That is a simplified explanation and is apparently only a problem on Windows 10. The Project Zero team successfully exploited the security flaw on Windows 10 version 1709. 

The issue is one of two reported by the Project Zero team. The first problem, Issue 1427, received a fix on February 13, whereas the issue listed in the public report published on Tuesday, February 20, (1428) was not. The Proof of Concept consists of software compiled in C++ executing as a normal user to create a file in the Windows folder using the “SvcMoveFileInheritSecurity” method. 

The issue Microsoft did fix is listed as CVE-2018-0826. According to the filing, Windows Storage Services “allows an elevation of privilege vulnerability due to the way objects are handled in memory.” It applies to Windows 10 versions 1511, 1607, 1703, and 1709 along with Windows Server 2016 and Windows Server version 1709. 

Google’s Project Zero team disclosed another vulnerability earlier this week that Microsoft has yet to fix. Originally disclosed to the company in November, the bug resides in Microsoft Edge and centers on a compiler for JavaScript. Hackers can compromise the browser by predicting the path of the compiling process. Unfortunately, Microsoft couldn’t provide a fix before the 90-day deadline. 

“The fix is more complex than initially anticipated, and it is very likely that we will not be able to meet the February release deadline due to these memory management issues,” the Microsoft Security Research Center stated. “The team is positive that this will be ready to ship on March 13th.” 

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
I upgraded from the M1 MacBook Air to the M5, and here’s what changed for me
The M5 changed more about my workflow than I expected.
Computer, Electronics, Laptop

After about four years with the M1 MacBook Air, I finally pulled the trigger on the M5, and I got there just in time to dodge Apple's recent price hike by eleven days, a story I already told elsewhere, and one that still makes me feel unreasonably smug. Upgrading from the M1 was a multi-generational leap for me, not in the ways mentioned on the spec sheet, but in ways that actually changed how I work every day.

Here’s why that matters in 2026, when the memory crisis has hit the consumer electronics market so badly that even giants like Apple had to cave. MacBook Air M5 launched at $1,099, then climbed to $1,299. 

Read more
Another Googlebook just surfaced online, and this one is from Asus
Asus Googlebook renders reveal a Glow Bar, plenty of ports, and a lightweight chassis
Computer, Electronics, Laptop

Google’s upcoming Googlebook lineup is starting to take shape through leaks. Lenovo has already appeared in several renders, while a recent benchmark leak suggests Dell may bring the XPS name to Google’s new laptop platform. Asus is now the latest manufacturer to surface ahead of launch.

Digital Citizen has published multiple renders of an unannounced Asus Googlebook, showing its lid, keyboard, chassis, and port selection. The laptop could make its official debut at IFA next month. Googlebooks are expected to bring Android apps, ChromeOS technology, deeper phone integration, and Gemini features to a new generation of laptops. Acer, Asus, Dell, HP, and Lenovo are all expected to be part of the first wave.

Read more
I’m done charging things that never leave my desk
Wireless peripherals are better than ever, but I’m starting to value the devices that ask absolutely nothing of me
Computer, Computer Hardware, Computer Keyboard

I have two pairs of wireless earbuds that I rotate during long gaming sessions. When one starts complaining about its battery, I swap in the other pair and put the first one on charge. It’s a mildly ridiculous system, but it works. Apparently, my gaming setup now requires something resembling shift work.

Then my mouse died in the middle of a game.

Read more