Security researcher uncovers security flaw in Internet Explorer that could be exploited by malicious hackers to launch convincing phishing attacks and inject malicious code into users browsers as they visit websites. The bug is a universal cross-site scripting (XSS) vulnerability, and bypasses what is known as the Same-Origin Policy. The vulnerability works on Internet Explorer 11 running Windows 7 or Wondows 8.1, but no timeline for a fix has been given. Microsoft has yet to issue a security patch for the bug, although no timeline has been provided.”]