Edge browser suffers security flaw which Microsoft failed to fix on time

Feb. 19, 2018

Google has found a vulnerability in Windows 10’s Edge browser, and the bad news is that this security bug has been disclosed to all and sundry before Microsoft could patch it.

The vulnerability can be used to sidestep Microsoft’s Arbitrary Code Guard (ACG) protection, leveraging a flaw in the browser’s JIT (Just-in-Time) compiler.

It’s classified as a “medium” severity flaw, so while not up there with the critical bugs, it’s definitely a hole which needs to be patched—and as noted, that hasn’t happened.

Google gave Microsoft the standard 90 days to fix the problem, and then an additional two weeks’ worth of time when the issue was found to be a more troublesome gremlin to remedy than first thought.

Unfortunately, even that fortnight extension wasn’t enough, so the vulnerability is now public knowledge and unpatched.

As Neowin reports, Microsoft is apparently confident that it will have the fix in line for the next big patch day on March 13. Of course, that’s still just over three weeks away.

And this delay really doesn’t look good for Microsoft, considering that the firm has had something of an uphill battle on the security front with Edge, the software giant has often talked-up the browser in terms of security, when the reality of this has sometimes fallen short, as we saw when Edge was found to be the least secure browser at Pwn2Own (a computer hacking contest held annually at the CanSecWest security conference) last year.

This certainly looks like a security slip, and won’t help Microsoft’s overall image in that respect. All that said, it’s clear that socks are being pulled up on the Edge team—for example, where phishing is concerned, Edge was rated the top browser in defending against that particular online evil in one report last October.

TechRadar has the full story

Sponsored Recommendations

The Healthcare Provider's Guide to Accelerating Clinician Onboarding

Improve clinician satisfaction and productivity to enhance patient care

ASK THE EXPERT: ServiceNow’s Erin Smithouser on what C-suite healthcare executives need to know about artificial intelligence

Generative artificial intelligence, also known as GenAI, learns from vast amounts of existing data and large language models to help healthcare organizations improve hospital ...

TEST: Ask the Expert: Is Your Patients' Understanding Putting You at Risk?

Effective health literacy in healthcare is essential for ensuring informed consent, reducing medical malpractice risks, and enhancing patient-provider communication. Unfortunately...

From Strategy to Action: The Power of Enterprise Value-Based Care

Ever wonder why your meticulously planned value-based care model hasn't moved beyond the concept stage? You're not alone! Transition from theory to practice with enterprise value...