
Edge halts in-memory loading of saved passwords at startup
Microsoft Edge will stop loading saved passwords into process memory at startup after a researcher demonstrated that credentials stored in Edge’s built-in password manager could be decrypted on launch and dumped from Edge processes. Microsoft initially claimed this behavior was by design but now says a defense‑in‑depth fix will be applied across all Edge channels (including Canary); the change is already live in Edge Canary and will roll out to all supported builds (build 148+). The PoC showed that attackers with admin rights could access passwords from Edge processes, though the threat model did not always cover such cases, and the update aims to reduce in‑memory exposure and strengthen Edge security overall.












