The last thing Internet Explorer needs another security incident. Its long-standing reputation problems, the failure of Microsoft Edge, and constant pressure from the corporate world do nothing to help the browser, but now we discover that its latest version has a bug that can leak everything we type into the address bar. While the hack requires designing a web page, the fact that the content typed into the bar becomes transparent to someone without authorization doesn't leave us very calm.
Internet Explorer. Yes, it still exists. No, Microsoft would prefer we stop using it. In a perfect world for Redmond, we'd all browse the web with Edge. I admit there's nothing fundamentally terrible about that browser, but it's the “many small details” that frustrate the average user and lead to resistance to its adoption. Who are the ones still on Internet Explorer today? For starters, a large part of the corporate world. Their rules are different, and compatibility isn't something they're willing to easily sacrifice. Then we find users on Windows 7 or Windows 8.x accustomed to IE's functionality, who see nothing tempting in their competitors' offerings. Nearly 10 percent of the market accesses the web with Internet Explorer, and if it suffers a security flaw, it's still important.
Security researcher Manuel Caballero from the Broken Browser portal discovered a flaw in the latest stable version of Internet Explorer that allows a malicious element to record everything the user types into the address bar. Whether it's a website, the IP address of a router, a private portal, or a simple search directed to the configured engine, the browser will leak that content. The proof of concept is a page that runs a script in the background and interrupts the process on purpose. If the attacker wishes, they can steal the address bar data and let the browser continue its course, with total transparency.
Microsoft spokespeople haven't said much about it. Everything seems to indicate that Internet Explorer isn't very high on their priority list, and any hotfix to correct this bug will arrive (in the best case) with the next round of patches.