Microsoft Edge will not support VML, VB Script, Toolbars, BHOs, or ActiveX to improve security
Microsoft Edge: Building a safer browser — With Microsoft Edge, we want to fundamentally improve security over existing browsers and enable users to confidently experience the web from Windows.
Context & Ripple Effects
Microsoft is using the launch of Edge to break with Internet Explorer's extensibility model: no VML, VBScript, toolbars, BHOs, or ActiveX, on the argument that native-code plugins are the main attack surface in Windows browsing. Two days earlier, Ars Technica's deep dive had already sketched the same architecture — a lean engine running high-performance asm.js instead of binary plugins, plus a new sandboxed extension system.
The pruning continued through the year, with Microsoft confirming Edge would also drop Silverlight, closing out the plugin era entirely. The security rationale proved durable: six years later Edge shipped "Super Duper Secure Mode," disabling V8's JIT to enable Arbitrary Code Guard, showing the launch-day trade-off — compatibility surrendered for attack-surface reduction — became a standing design principle.
First-order effects
- Enterprises running ActiveX-dependent intranet applications lose their default upgrade path to Edge and must keep Internet Explorer alive alongside it.
- Vendors whose products were BHOs, toolbars, or ActiveX controls lose their distribution mechanism in the new default Windows browser overnight.
Second-order effects
- Web developers get pressure to rewrite legacy line-of-business apps against standards-based APIs, since the Windows default browser will not load their old controls.
- Edge's JIT-optional hardening raises the bar competitors are measured against, pushing security comparisons toward memory-safety features rather than plugin blocklists.
Third-order effects
- The pattern ends where Edge's extension policy now does: with Microsoft phasing out Manifest V2 extensions starting this month and for enterprises in early 2027, following Chrome — extensibility itself migrating from whatever installs natively to a centrally curated, periodically deprecated API surface.
- If the arc holds, the browser stops being an open host for third-party native code altogether, becoming a sandboxed runtime whose capabilities are granted and revoked by the vendor — the premise behind treating the browser as a delegated point of control.
The trend: Browsers are replacing permissive native extensibility — plugins, controls, toolbars — with vendor-curated, sandboxed extension platforms that can be tightened or retired at will.