Serious Discussion Microsoft Edge Stable (Chromium) Now Available for Download

silversurfer

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,048
Version 96.0.1054.29: November 19

Microsoft has released the latest Microsoft Edge Stable Channel (Version 96.0.1054.29), which incorporates the latest Security Updates of the Chromium project. For more information, see the Security Update Guide.

This update contains the following Microsoft Edge-specific updates:
 

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,814
Probably, but it'll be one more bloated invasive "feature" to disable.

Every update requires a stroll through the settings to disable, disable, disable ...
Yeah, I'm getting a little tired of the bloat too.

Speaking of a stroll through the settings:
Screenshot 2021-11-20 095310.png
This is new, right? (Settings > Privacy, search and services > Security)
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,505
Yeah, I'm getting a little tired of the bloat too.

Speaking of a stroll through the settings:
View attachment 262083
This is new, right? (Settings > Privacy, search and services > Security)
This is Microsoft Edge’s Super Duper Secure Mode previously only available in edge://flags:
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,505
Version 96.0.1054.29: November 19
Stable channel security updates are listed here.
Feature updates
  • Cloud Site List Management for IE mode in Public Preview. Cloud Site List Management lets you manage your site lists for IE mode in the cloud without needing an on-premises infrastructure to host your organization's site list. You can access the Cloud Site List Management feature using the Microsoft Edge Site Lists experience in the Microsoft 365 Admin Center. To learn more, see the Cloud Site List Management for IE mode (Public Preview) article.
  • Improved handoff between IE mode and the modern browser. Starting with this version of Microsoft Edge, navigations between Microsoft Edge and Internet Explorer mode will include form data and additional HTTP headers. Referrer headers, post data, forms data, and request methods will be forwarded correctly across the two experiences. You can specify which data types should be included using the InternetExplorerIntegrationComplexNavDataTypes policy. For more information, see this FAQ: My application requires transferring POST data between IE mode and Microsoft Edge. Is this supported?
  • Update Microsoft Edge WebWiew2 using WSUS. IT Admins using Windows Server Update Services (WSUS) to update Microsoft Edge will also be able to update Microsoft Edge WebView2 using WSUS. This capability gives admins an easier servicing process for offline devices.
  • WSUS updates for Server. WSUS and Catalog updates for Microsoft Edge channels (Stable, Beta, and Dev) will now apply to Windows Server SKUs that have Microsoft Edge installed, including Windows Server 2022. For more information on how to configure WSUS updates for Microsoft Edge, see Update Microsoft Edge.
  • Microsoft Edge AutoLaunch Protocols Component. Microsoft Edge 96 introduces the AutoLaunch Protocols Component that contains lists of scheme-origin dictionaries to automatically allow or block. This protects customers from dangerous schemes (for example, a protocol handler with a 0-day) while eliminating prompts from known-safe pairings (for example, the Teams website can open the Teams client app). If for some reason, you don't want Microsoft Edge to block vulnerable protocol handlers and allow known-safe pairings, use the toggle in edge://settings/content/applicationLinks, or set the AutoLaunchProtocolsComponentEnabled policy to False.
  • Launch Progressive Web App (PWA) directly via protocol links. Let installed PWAs handle links that use a specific protocol for a more integrated experience.
  • Quickly view Office files in the browser. Users can now view Office files including documents, spreadsheets, and presentations that they come across while browsing on Microsoft Edge right in the browser without needing to download the file and then open it in a different application. There will be no changes in the file open experience for Office files that are hosted on OneDrive or SharePoint.
  • Freeform highlighting on PDFs. The PDF viewing and markup experience is improved with the addition of freeform highlighters. You can highlight sections in PDFs that you don't have access to, and scanned documents.
  • New warning dialog for typosquatting sites. The browser will show a warning on some sites with URLs that look very similar to other sites. This UI uses client-side heuristics to warn users about sites that might be spoofing popular web sites. For more information, see What is typosquatting?.
  • Dictionary added to mini-toolbar in Immersive Reader. We're adding dictionary functionality to the mini-toolbar to assist in your reading and research. You'll be able to look up the spelling and definitions of words more quickly and easily in the Immersive Reader experience.
  • Learn how to solve math problems with Math Solver. We’re excited to announce that you can use Math Solver in Microsoft Edge to get help with a wide range of mathematical concepts. These concepts range from elementary arithmetic and quadratic equations to trigonometry and calculus. Math Solver lets you take a picture of a handwritten or printed math problem and then provides an instant solution with step-by-step instructions to help you learn how to reach the solution without help. Math Solver also comes with a mathematical keyboard that you can use to easily type math problems. This keyboard eliminates the need to search around a traditional keyboard to find the math characters you need. After solving your problem, Math Solver provides options to continue learning with quizzes, worksheets, and video tutorials.
 

SeriousHoax

Level 47
Well-known
Mar 16, 2019
3,630
This new version 96 has broken the forced dark mode that's available on flags. The name used to be "Forced Dark Mode for Web Contents" I think and now it's called "Auto Dark Mode for Web Contents". Some things are not darken properly anymore. They are now instead inverse colored/negative/black & whitish.
This issue is Chromium related. Just checked Chrome, and it's the same there also.
It's not happening on all the places, only on some.
Look at those reactions, lol.
1.png2.png4.png3.png
 

oldschool

Level 81
Verified
Top Poster
Well-known
Mar 29, 2018
7,043
V. 96 update requires (practically) enforced jigsaw icon on toolbar for easiest access to extensions page. (Two clicks) No quick access via hamburger menu. (Three clicks)

@Arequire yes this is new. Is this "Super duper secure mode" -now available by default via Settings > Privacy and security > ? :unsure: SDSM flag still available.

1637434861684.png
 
Last edited:
F

ForgottenSeer 92963

@oldschool

Superduper mode 'only' disables the Javascript just in time compiler. Edge has more flags related to security. I tred a few, but they broke the websites I have in my bookmarks. Edge tracking protection already monitors my engagement with websites (baed on wether it is bookmarked and my clicking behavior on that website). So they have a mechanisme to see whether I frequently visit that website (bookmarks).

Edge can apply stronger mitigaties for websites I do not visit often (not bookmarks and not in the known website list of Smartscreen) when I visit a new website how interact with a website (click behavior) and how many other people visit that website (Smartscreen statistics). So this part of Edge can be trained with an artificial intelligence system to decide whether less or more restrictions should be applied.

I have a separate shortcut for my hard-mode profile in which I also use the --inprivate start switch. Today I checked the list of blocked trackers in my hard-mode profile and it reported zero trackers blocked. It seems that Microsoft respects the privacy promise of its incognito mode (which M$ calls inprivate mode). Assuming the new feature uses the same user-engagement monitor as tracking protection, I trust this new security strict mode with --inprivate will also nullify the visited sites statistics.

I am using two profiles, because SecurityNightmares posted a thread on the benefits of using three profiles. Because I never ran into troubles with my easy mode profile, I dumped the completely default profile for banking and now am using easy-mode for banking also (disabling uBO for my bank only). The two profiles (easy and hard mode) have different settings on how I interact with my browser, site permissions, Edge build in privacy and security and different uBO modes and blocklists.
 
Last edited by a moderator:
  • Like
Reactions: oldschool
F

ForgottenSeer 92963

Good news AppContainer is coming back, you can enable it now through registry hack or group policy. but it will return (automatically)in next versions

1637514631038.png


With Code Integrity Guard (enabled for renderer process automatically) and AppContainer for renderer process and new security mitigation feature, Microsoft Edge browser will be the safest Chromium based browser by far (y)(y) (y) (and don't forget old de-elavation on launch of renderer process (y))

Micrsoft Defender with Configure Defender enabling ASR for you, Defender is top notch when you use Microsoft office, Defender will also be top notch when you use Edge Browser (no disabling of build-in security features needed to monitoring the browser by third-party AV). I never thought I would become an enthousiastic user of Microsoft security (old Avira/SSM/GeSWall user on XP and Avast/ThreatFire/DefenseWall user on Vista).
 
Last edited by a moderator:
F

ForgottenSeer 92963

@oldschool was right the new security mitigations settings are the super-duper-mode according to this post Microsoft Edge's Super Duper Secure Mode lands in Settings - gHacks Tech News

By disabling JIT it is possible to enable CET (when your processor supports this) and Arbitrary Code Guard (ACG) . I checked by disabling and enabling Super-Duper-Mode (SDM) with Arbitrary Code Guard and when SDM was enabled Edge started normally with ACG enabled. With SDM disabled Edge hanged with ACG enabled. A few websites broke when enabling ACG, so disabled again for Edge.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top