Microsoft Edge Criticized for Storing Passwords in Plaintext in RAM
Security researcher Tom Joran Sonstebyseter Ronning discovered that Microsoft Edge stores user passwords in plaintext within the computer's RAM. Unlike Google Chrome, which loads passwords only when specifically challenged and clears them from memory after use, Edge loads all stored passwords upon a single verification check and retains them in memory indefinitely. This design allows attackers with access to the system's memory to dump and recover credentials easily. Microsoft downplayed the severity of the vulnerability, stating that exploiting it requires the device to be already compromised by malware or similar threats. The company emphasized that this behavior is an expected feature designed to balance performance and usability for quick sign-ins. However, Ronning countered that the flaw poses additional risks, as users with administrative privileges could potentially access passwords belonging to other logged-on users. Microsoft advised users to maintain up-to-date security software and install the latest updates to mitigate such threats, while acknowledging that they continuously review design choices against evolving security landscapes.
Wire timeline
Microsoft Edge Criticized for Storing Passwords in Plaintext in RAM
Security researcher Tom Joran Sonstebyseter Ronning discovered that Microsoft Edge stores user passwords in plaintext within the computer's RAM. Unlike Google Chrome, which loads passwords only when specifically challenged and clears them from memory after use, Edge loads all stored passwords upon a single verification check and retains them in memory indefinitely. This design allows attackers with access to the system's memory to dump and recover credentials easily. Microsoft downplayed the severity of the vulnerability, stating that exploiting it requires the device to be already compromised by malware or similar threats. The company emphasized that this behavior is an expected feature designed to balance performance and usability for quick sign-ins. However, Ronning countered that the flaw poses additional risks, as users with administrative privileges could potentially access passwords belonging to other logged-on users. Microsoft advised users to maintain up-to-date security software and install the latest updates to mitigate such threats, while acknowledging that they continuously review design choices against evolving security landscapes.
Slashdot