By Design No More: Microsoft Edge Vv148.0 to Block Plaintext Password Scrapes from Process Memory
ID: fc1cf99d-6a57-5b0f-938b-1a24aadf8149
STIX ID: report--fc1cf99d-6a57-5b0f-938b-1a24aadf8149
Feed Name: securityonline.info
Threat Score
A researcher reported that Microsoft Edge loads cached user credentials as cleartext into active memory on startup. Microsoft initially declined to classify this as a vulnerability or issue a bug bounty because exploitation requires local, privileged execution, but announced an engineering remediation and has implemented a Canary fix to stop ingesting unencrypted credentials into volatile memory; the fix will be delivered in Edge v148.0 Stable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
