Microsoft reverses course on Edge password handling but denies users were ever at risk
windowscentral.com May 16, 2026

Microsoft reverses course on Edge password handling but denies users were ever at risk

AI-summarised brief · reviewed before publication

Microsoft Edge will no longer load all passwords into memory in plaintext on startup, a change announced after a security researcher discovered the behavior. The researcher found that Edge decrypts every credential on startup, keeping the data in memory, unlike Chrome which only decrypts specific passwords when requested. Microsoft initially stated the behavior was not a security concern, requiring a compromised device to access the data. However, the company is updating Edge to version 148, changing the behavior to improve security, with the update already live in the Canary Channel and rolling out to all users soon. The change is seen as a precautionary measure, despite Microsoft's assertion that the original behavior was not a serious risk. The update aims to improve Edge's security.

💡 Why It Matters

  • · Microsoft's swift reversal underscores the importance of proactive security measures, even when initial risks seem low.
  • · By changing Edge's password handling, Microsoft acknowledges the potential for improved security.