Skip to content
Microsoft Edge Exposes Saved Passwords in Cleartext Memory

Microsoft Edge Exposes Saved Passwords in Cleartext Memory

First seen 5 May 2026, 07:03 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 6, 2026 at 06:42 UTC
  • Microsoft Edge stores passwords in cleartext in process memory at startup.
  • The vulnerability is confirmed by multiple sources and is deemed a significant security risk.
  • Microsoft claims this behavior is 'by design,' which has been criticized by security experts.

A researcher has discovered that Microsoft Edge saves all passwords in cleartext in process memory upon startup, regardless of whether the user has accessed the sites. This vulnerability, identified by Tom Jøran Sønstebyseter Rønning, poses significant risks for users, especially in shared environments. The issue was confirmed by multiple sources, including Heise.de and Cybersecuritynews. Microsoft has stated that this behavior is 'by design,' which has drawn criticism from security experts who argue it compromises user security. Other browsers, such as Google Chrome, employ better security practices to encrypt stored passwords. Rønning plans to release a tool on GitHub to demonstrate the vulnerability. The lack of urgency from Microsoft raises concerns about the company's commitment to user security. This issue affects all users of Microsoft Edge who save passwords within the browser.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 129d ago How this analysis works

Timeline

2026-04-29
Researcher discloses Edge password storage issue.
2026-05-04
Discussion of the issue on social media platform X.
2026-05-05
Multiple articles published covering the vulnerability.

More articles in this cluster (17)

Following this threat?

Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed