logo

Microsoft is changing Edge’s plaintext password behavior

ID: a8144afe-3f7d-5f6f-a4f6-f909dbed7ce7

STIX ID: report--a8144afe-3f7d-5f6f-a4f6-f909dbed7ce7

Feed Name: Malwarebytes Blog

Threat Score
30/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

Microsoft Edge previously decrypted the entire saved-password store on startup and kept credentials in clear text in process memory for the browser session; after researcher disclosure, Microsoft changed Edge (already in Canary) to decrypt passwords only when needed for autofill or management, reducing the risk of mass password harvesting from process memory and rolling the fix out across channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.