Google’s Project Zero discloses Edge browser bug after Microsoft didn’t fix it in time
Microsoft didn't make the 90-day patch window, so Project Zero shared details with the world

Google's Project Zero security team has disclosed a Microsoft Edge flaw after the Redmond firm didn't manage to fix it in time.
Details of the security bypass bug were originally shared with Microsoft on 17 November last year, but because Microsoft wasn't able to come up with a suitable patch within Google's non-negotiable 90-day fix period, the security researchers made it public.
Project Zero usually gives software companies an extension of 14 days on that 90-day window if a patch is close, but in Microsoft's case it wasn't.
Exactly 90 days post-discovery, Google revealed Microsoft's excuse, quoting: "The fix is more complex than initially anticipated, and it is very likely that we will not be able to meet the February release deadline due to these memory management issues.
"The team IS positive that this will be ready to ship on March 13th [2018-03-13], however this is beyond the 90-day SLA [service level agreement] and 14-day grace period to align with Update Tuesdays."
Google therefore published details of the bug immediately, revealing to Microsoft Edge users how they are to be without a patch for almost another month.
Luckily, the bug isn't too dangerous. Security firm Sophos pointed out that it isn't as bad as a remote code execution exploit. It's in fact a security bypass that could allow an attacker who has already wrested control from a user's browser to get past Microsoft's second layer of defence, known as an Arbitrary Code Guard (ACG).
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"ACG is supposed to head off remote code execution attacks before they can make any headway," explained Sophos's Paul Ducklin in a blog post. "Very simply put, [it] works by locking down the memory that Edge uses to run its own software code."
An attacker who uses the flaw to get control via a webpage that Edge just loaded can't modify executable code that's already in memory, nor can they allocate new memory blocks in which to store rogue code, so Sophos suggested Edge users shouldn't worry too much about it.
"[While] this hole doesn't give crooks a direct way to take over your browser immediately, [Edge users] can regard it as a vulnerability that could make a bad thing worse, rather than a bad thing in the first place," Ducklin added.
Nevertheless, it's always best to keep your computer as safe as possible, so if you're an Edge browser user, look out for Microsoft's forthcoming patch. It might be that it's included in its next Patch Tuesday release.
Image: Shutterstock
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Busting nine myths about file-based threats
Whitepaper Distinguish the difference between fact and fiction when it comes to preventing file-based threats
By ITPro Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
The Total Economic Impact™ of the Intel vPro® Platform as an endpoint standard
Whitepaper Cost savings and business benefits enabled by the Intel vPro® Platform as an endpotnt standard
By ITPro Published
-
The Total Economic Impact™ of IBM Security MaaS360 with Watson
Whitepaper Cost savings and business benefits enabled by MaaS360
By ITPro Published
-
WithSecure Elements EPP and EDR review: Endpoint protection on a plate
Reviews An affordable cloud-managed solution with smart automated remediation services
By Dave Mitchell Published
-
Supply chain as kill chain
Whitepaper Security in the era Zero Trust
By ITPro Published
-
KuppingerCole leadership compass report - Unified endpoint management (UEM) 2023
Whitepaper Get an updated overview of vendors and their product offerings in the UEM market.
By ITPro Published
-
The Total Economic Impact™ of IBM Security MaaS360 with Watson
Whitepaper Get a framework to evaluate the potential financial impact of the MaaS360 on your organization
By ITPro Published