Microsoft is changing Edge’s plaintext password behavior
ID: a8144afe-3f7d-5f6f-a4f6-f909dbed7ce7
STIX ID: report--a8144afe-3f7d-5f6f-a4f6-f909dbed7ce7
Feed Name: Malwarebytes Blog
Threat Score
Microsoft Edge previously decrypted the entire saved-password store on startup and kept credentials in clear text in process memory for the browser session; after researcher disclosure, Microsoft changed Edge (already in Canary) to decrypt passwords only when needed for autofill or management, reducing the risk of mass password harvesting from process memory and rolling the fix out across channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
