logo

By Design No More: Microsoft Edge Vv148.0 to Block Plaintext Password Scrapes from Process Memory

ID: fc1cf99d-6a57-5b0f-938b-1a24aadf8149

STIX ID: report--fc1cf99d-6a57-5b0f-938b-1a24aadf8149

Feed Name: securityonline.info

Threat Score
30/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

A researcher reported that Microsoft Edge loads cached user credentials as cleartext into active memory on startup. Microsoft initially declined to classify this as a vulnerability or issue a bug bounty because exploitation requires local, privileged execution, but announced an engineering remediation and has implemented a Canary fix to stop ingesting unencrypted credentials into volatile memory; the fix will be delivered in Edge v148.0 Stable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.