Edge Buries Saved Passwords in RAM in Plaintext, Study Finds
TL;DR
Security researcher finds that Microsoft Edge loads all saved passwords into memory in cleartext on startup and keeps them in memory for the entire session, making them easier to harvest by memory reading; Microsoft says the behavior is by design, and exploit would require admin access; experts urge against storing passwords in browsers and recommend MFA or passkeys.
- Microsoft Edge keeps cleartext passwords in RAM, security researcher warns Cybernews
- Microsoft Edge is storing passwords as plain text? Here's what Microsoft says. Mashable
- Microsoft Says Edge Password Security Vulnerability Is ‘By Design’—Is It Time To Switch To Chrome? Forbes
- Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk Dark Reading
- Microsoft Edge: Passwords end up in memory as plaintext heise online
Want the full story? Read the original reporting
Read on Cybernews