logo

Why Edge stores your passwords in plaintext, according to Microsoft

ID: 2f628249-a295-555b-8c52-e7feaab74e2e

STIX ID: report--2f628249-a295-555b-8c52-e7feaab74e2e

Feed Name: ZDNet Security

Threat Score
50/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

...
...

A researcher demonstrated that Microsoft Edge's password manager decrypts and retains saved credentials in plaintext in the browser process memory, allowing an attacker with access to a device's memory (e.g., via local compromise or administrative access) to extract passwords; Microsoft calls this an expected design tradeoff and recommends keeping devices updated and protected, while the article advises using dedicated third-party password managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.