Isc.Sans.Edu Microsoft Edge Exposes Saved Passwords in Cleartext Memory
Article Content
- •Microsoft Edge stores passwords in cleartext in process memory at startup.
- •The vulnerability is confirmed by multiple sources and is deemed a significant security risk.
- •Microsoft claims this behavior is 'by design,' which has been criticized by security experts.
A researcher has discovered that Microsoft Edge saves all passwords in cleartext in process memory upon startup, regardless of whether the user has accessed the sites. This vulnerability, identified by Tom Jøran Sønstebyseter Rønning, poses significant risks for users, especially in shared environments. The issue was confirmed by multiple sources, including Heise.de and Cybersecuritynews. Microsoft has stated that this behavior is 'by design,' which has drawn criticism from security experts who argue it compromises user security. Other browsers, such as Google Chrome, employ better security practices to encrypt stored passwords. Rønning plans to release a tool on GitHub to demonstrate the vulnerability. The lack of urgency from Microsoft raises concerns about the company's commitment to user security. This issue affects all users of Microsoft Edge who save passwords within the browser.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…