Skip to content

// #process-dump

1 article

🏛️ Architecture

Microsoft Edge Stores Saved Passwords as Plaintext in Process Memory — No CVE, No Patch

Security researchers have documented that Microsoft Edge's built-in password manager stores user-saved passwords in cleartext within the browser's process memory — readable by any process on the same system with the ability to dump Edge process memory. Microsoft has acknowledged the behaviour and characterised it as a performance design decision, not a vulnerability warranting a security fix. Users relying on Edge's password manager for credential storage should understand what this means for their threat model.

#microsoft-edge +6