Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
ID: d6fce0fe-f06b-5344-bfc3-b84f43b19882
STIX ID: report--d6fce0fe-f06b-5344-bfc3-b84f43b19882
Feed Name: cybersecurityNews.com
Threat Score
Microsoft Edge decrypts and loads every saved password into cleartext process memory at browser startup and retains them for the session, making all stored credentials accessible to any local process with memory-read capabilities; a proof-of-concept shows an admin on Remote Desktop/terminal server environments harvesting credentials from other logged-on users, and Microsoft currently considers this behavior "by design."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
