Microsoft Edge 146 Introduces Expanded IP Privacy Protections & New Enterprise Network Controls
Microsoft has released version 146 of the Microsoft Edge browser to the Stable channel, introducing updates aimed at improving user privacy protections, enterprise security management, and network access controls. The release, which became available on March 13, 2026, continues Microsoft’s efforts to strengthen browser-based defenses against tracking and unauthorized network interactions while aligning the browser with evolving web security standards.
The update introduces several notable changes, including expanded IP address privacy protections, simplified private browsing settings, enhanced enterprise network policies, and updated data-management behavior within the browser. In addition, Edge 146 integrates the latest security patches inherited from the Chromium open-source project, ensuring continued compatibility with the underlying engine shared by many modern browsers.
One of the most visible adjustments in Edge 146 involves how tracking prevention settings apply in InPrivate browsing mode.
Previously, Edge allowed users to configure a separate tracking prevention level specifically for private browsing sessions. With this release, Microsoft has removed that distinction. Instead, InPrivate windows now automatically use the same tracking prevention level selected for standard browsing sessions.
This means that if a user has chosen Basic, Balanced, or Strict tracking prevention in their normal browsing settings, the same configuration will apply automatically in private windows.
Microsoft says the change simplifies the browser’s privacy configuration and helps avoid situations where different settings between normal and private browsing could lead to confusion or inconsistent protection.
InPrivate browsing itself continues to function as a privacy feature designed to prevent the browser from storing:
browsing history cookies and site data form inputs temporary files
once the private window is closed.
Another significant update in Edge 146 involves IP privacy protections through an expanded feature called Private IP, which is part of the browser’s Edge Secure Network system.
The Secure Network feature functions similarly to a lightweight VPN, routing certain web traffic through Microsoft-operated network infrastructure before it reaches the destination website.
In the new update, Edge can now automatically route traffic from known tracking domains through this secure network path, helping prevent websites from identifying a user through their public IP address.
IP addresses are widely used by websites for purposes such as:
geolocation fraud detection advertising targeting tracking user activity across sites
Unlike a full VPN service, however, the Secure Network system typically applies selectively to known tracking endpoints rather than all web traffic.
Microsoft has positioned the feature as part of a broader push to reduce fingerprinting and tracking techniques that rely on network identifiers.
Edge 146 also introduces a notable change to the browser’s Clear Browsing Data controls.
In versions, users could select saved passwords as part of the items deleted when clearing browsing data. In the new update, passwords have been removed from that list entirely.
Instead, password removal and management now remain exclusively within Edge’s built-in password manager.
This change separates sensitive account credentials from routine browsing cleanup actions. Microsoft says the goal is to reduce the risk that users accidentally delete stored passwords while attempting to clear cookies, cache files, or browsing history.
Edge’s password manager continues to support:
automatic password generation password leak monitoring synchronization across devices secure autofill for websites
These tools are integrated with the user’s Microsoft account and protected by system authentication such as Windows Hello when available.
For corporate and managed environments, Edge 146 introduces new Local Network Access (LNA) policies designed to help organizations better control how websites interact with devices on internal networks.
The policies allow administrators to define rules governing whether websites are allowed to send requests to local network endpoints, such as printers, routers, internal services, or other connected devices.
Under the new framework, administrators can:
define trusted IP address ranges within a local network specify which websites are permitted to access those ranges block untrusted websites from communicating with local devices
This capability addresses a growing security concern involving browser-based attacks against local infrastructure.
In some cases, malicious websites have attempted to exploit browser features to send requests to devices within a user’s internal network, potentially exposing:
configuration interfaces IoT devices internal APIs administrative panels
The feature aligns with broader industry efforts to strengthen the browser’s role as a security boundary between the internet and local networks.
Another enterprise-focused enhancement in Edge 146 involves expanded administrative control over Transport Layer Security (TLS) behavior.
Administrators can now configure policies that prioritize specific TLS cipher suites and key exchange algorithms. This level of control is particularly useful for organizations operating in regulated environments where encryption standards must meet strict compliance requirements.
TLS is the cryptographic protocol responsible for securing most web traffic, including HTTPS connections. By allowing administrators to define preferred encryption settings, Edge enables organizations to:
enforce modern cryptographic standards disable weaker or deprecated algorithms ensure compatibility with internal security infrastructure
This functionality can be especially important in sectors such as finance, healthcare, government, and critical infrastructure , where encryption policies often follow strict regulatory frameworks.
As with most Edge releases, version 146 also includes security patches inherited from the Chromium project , the open-source browser engine that Edge shares with other browsers such as Google Chrome.
This update includes two security fixes. one addressing CVE-2026-3910 , a Chromium vulnerability reported to be actively exploited in the wild, and another for CVE-2026-0385, which affects Microsoft Edge specifically.
CVE-2026-3910 - Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Severity: High)
CVE-2026-0385 - Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability. An attacker could host a specially crafted website designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action, typically by an enticement in an email or instant message, or by getting the user to open an attachment sent through email.
Exploitation of the vulnerability requires that a user open a specially crafted file. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.
Chromium updates regularly address vulnerabilities affecting components like:
rendering engines JavaScript execution network processing memory handling
Regular Chromium synchronization has become a standard part of Edge’s release cycle since Microsoft transitioned the browser to the Chromium engine in 2020.
The release of Edge 146 reflects a broader industry trend toward strengthening browser-level privacy protections and tightening enterprise security controls.
Web browsers have increasingly become central to both personal computing and enterprise workflows, meaning improvements to tracking protection, encryption management, and network access policies can have significant security implications across millions of users and organizations.
Edge 146 is now available through automatic updates on Windows, macOS, and Linux, with enterprise administrators able to deploy the update through standard organizational management tools.
Access complete Microsoft Edge changelog HERE . To manually update your copy of Microsoft Edge, go to edge://setting/help.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
