Researcher Reveals Microsoft Edge Loads Stored Passwords in Plaintext
A security researcher has discovered that Microsoft Edge decrypts and stores all saved passwords in plaintext within the computer's RAM upon startup, regardless of whether the associated websites are visited. This design choice potentially allows malware with administrative privileges to easily extract login credentials. The researcher, Tom Jøran Sønstebyseter Rønning, demonstrated this vulnerability using simple command-line tools, noting that Edge is unique among Chromium-based browsers for this behavior. In contrast, competitors like Google Chrome only decrypt specific credentials when needed for autofill and clear them from memory afterward. Microsoft defended the practice as a deliberate design choice aimed at balancing performance and usability, arguing that the threat model requires the device to be already compromised by malware or an attacker with admin access. However, critics argue that Microsoft should adopt stronger security measures similar to other browsers to protect user data even in compromised scenarios. The revelation has sparked debate within the cybersecurity community regarding the adequacy of Windows' built-in security features and the necessity for browsers to minimize the exposure of sensitive data in memory.
Wire timeline
Researcher Reveals Microsoft Edge Loads Stored Passwords in Plaintext
A security researcher has discovered that Microsoft Edge decrypts and stores all saved passwords in plaintext within the computer's RAM upon startup, regardless of whether the associated websites are visited. This design choice potentially allows malware with administrative privileges to easily extract login credentials. The researcher, Tom Jøran Sønstebyseter Rønning, demonstrated this vulnerability using simple command-line tools, noting that Edge is unique among Chromium-based browsers for this behavior. In contrast, competitors like Google Chrome only decrypt specific credentials when needed for autofill and clear them from memory afterward. Microsoft defended the practice as a deliberate design choice aimed at balancing performance and usability, arguing that the threat model requires the device to be already compromised by malware or an attacker with admin access. However, critics argue that Microsoft should adopt stronger security measures similar to other browsers to protect user data even in compromised scenarios. The revelation has sparked debate within the cybersecurity community regarding the adequacy of Windows' built-in security features and the necessity for browsers to minimize the exposure of sensitive data in memory.
PCMag.com - Technology Product Reviews, News, Prices & Tips