Decrypted and Vulnerable: Why Microsoft Edge Keeps All Your Passwords in Plaintext Memory
ID: 13be96d6-90ae-5d15-bfeb-01130bbb69ff
STIX ID: report--13be96d6-90ae-5d15-bfeb-01130bbb69ff
Feed Name: securityonline.info
**Executive Summary:** Security researcher Tom found that Microsoft Edge loads all stored account credentials into plaintext in system memory at initialization and retains them in the parent process, which allows an actor with elevated (administrative) privileges on Windows 10/11 shared workstations to exfiltrate saved passwords; Microsoft has treated this as a deliberate design choice and declined a bug bounty while the researcher published a proof‑of‑concept and recommends users sign out of shared machines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
