logo

Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)

ID: 20eb2fab-66ab-5f68-90c5-013c52a9ec41

STIX ID: report--20eb2fab-66ab-5f68-90c5-013c52a9ec41

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

...
...

The author demonstrates that Microsoft Edge keeps saved usernames and passwords in cleartext within the browser process memory; by creating a memory dump of the Edge "browser" subprocess and running strings (filtered for patterns like "comhttps"), stored credentials can be trivially recovered. The post includes reproduction steps, screenshots, and notes that Microsoft classifies the behavior as "intended," warning that any malware running as the logged-in user could harvest these credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.