Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
AI-summarised brief · reviewed before publication
A security researcher discovered Microsoft Edge stores all saved passwords in cleartext process memory at launch, regardless of site visits. This behavior, unique to Edge among major Chromium-based browsers, creates a wide-surface extraction target for attackers. Edge loads the entire password vault into plaintext process memory at startup, contrasting with Google Chrome's on-demand decryption and App-Bound Encryption. This poses significant risks, especially in shared environments.
💡 Why It Matters
- · Administrative privileges can be used to extract credentials from multiple users simultaneously, transforming a single compromise into a full credential harvest.
- · This directly maps to known attack techniques, enabling widespread credential theft.