Researcher Shows Edge Browser Stores Saved Passwords in Plaintext
ID: f640a705-5848-5ac9-9a42-79b8144f94b1
STIX ID: report--f640a705-5848-5ac9-9a42-79b8144f94b1
Feed Name: HackRead
A researcher demonstrated that Microsoft Edge stores saved passwords in plaintext in process memory and released a proof-of-concept tool (EdgeSavedPasswordsDumper) showing how an attacker or infostealer with sufficient privileges can extract credentials; this is especially risky in shared environments (Citrix/VDI). Microsoft says the behavior is by design and recommends using dedicated password managers and other mitigations, while experts warn the transient plaintext presence in memory makes passwords easily harvestable by other processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
