Microsoft Edge Update Prevents Saved Passwords from Loading at Startup
ID: e2a98f8e-1e26-58e1-be24-db7541f04de3
STIX ID: report--e2a98f8e-1e26-58e1-be24-db7541f04de3
Feed Name: Cyber Press
Threat Score
Microsoft Edge previously decrypted and loaded all saved passwords into process memory in cleartext at browser startup, enabling local attackers or tools (including a published PoC) to extract credentials; Microsoft issued a defense-in-depth update (Edge build 148+) to stop loading passwords at startup and recommended mitigations such as monitoring for memory-dumper tools and updating managed endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
