The Edge Security team relentlessly bolsters defenses, erecting fresh barriers to thwart any attempts at escaping the Renderer sandbox 🛡️🔒
https://t.co/t8m3piI0I3
Our first Edge bounty case that highlighted an Adobe PDF RCE within the product: CVE-2023-44323.
Vuln impacts Adobe Acrobat for Edge version 118.0.2088.46 (and earlier)
https://t.co/DMQt7Y3yk2
Edge rolled out a fix to the latest 0day (CVE-2023-3079) and, once again, if opt-ed into Enhanced Security Mode it will help mitigate this JIT related vulnerability 😍
Can we just turn ESM on by default on Edge ?
https://t.co/erAKE92qwm
Edge released 112.0.1722.54 addressing the latest 0day (CVE-2023-2136). It does not impact Windows, but other OS (like Linux, macOS, and Android)
https://t.co/UKqCer72es
Another chromium JIT 0day. Luckily, Edge's enhanced security mode helps mitigate this vulnerability🙂.
Edge's security patch will roll out soon, but until then, I will continue to be super duper secure.
https://t.co/dWuEHsYymI
Microsoft Edge has rolled out Stable 108.0.1462.42 which contains over >20 security fixes - also including the latest Chromium 0-day (CVE-2022-4262)
Did you know that the latest Chromium 0-day (CVE-2022-3723) is mitigated by Edge's enhanced security mode? Kind of super duper 😉
We know ESM disabled all JIT compilation, including JS, so any bug in v8/src/compiler can't affect users with ESM enabled
During the weekend, Microsoft Edge rolled out Stable 107.0.1418.26 and Extended Stable 106.0.1370.61.
Both containing the latest Chromium 0-day fix (CVE-2022-3723).
Our Release Notes will be updated shortly.
@spoofyroot@bmastenbrook Currently, we do not have a timeframe for them as we want to hear some initial feedback from one platform before spreading ourselves too thin - avoiding a whack-a-mole game across multiple platforms. But October is one my favorite months😉
Microsoft Edge just released the security fix for CVE-2022-3075 with 105.0.1343.27. This is an exploit that exists in the wild so don't forget to patch before the long weekend 😉
Did you hear?
Enhanced Security Mode now supports WASM under all preferences (currently only on Windows x64 platforms). This is super duper #MicrosoftEdge
Edge 105 will release to stable this week and include WASM support for Enhanced Security Mode on Windows x64 platforms. So far millions of users have tried jitless browsing and seem to enjoy it, despite the claims it would be too slow. 1/