Microsoft Edge is reportedly keeping saved passwords readable in memory

news
Microsoft Edge is reportedly keeping saved passwords readable in memory

Microsoft Edge’s built in password manager is facing scrutiny after a security researcher found that saved passwords can appear in a readable form in system memory.

The issue was raised by Norwegian security researcher Tom Jøran Sønstebyseter Rønning, who showed that Edge can load saved passwords into RAM as plain text. According to the report, this can happen even when those passwords are not being actively used during the browsing session.

That matters because a person or malicious program with local access to the device could read the system memory and collect saved credentials. Edge still asks for authentication when you try to view saved passwords through the browser’s password manager, but that protection may not help if the passwords can be taken directly from RAM.

Browser password managers normally decrypt passwords only when needed, then remove them from memory after use. Rønning said Edge behaved differently from other Chromium based browsers he tested.

Microsoft reportedly told the researcher that this behavior was intentional rather than a bug. That answer makes the finding more concerning because it suggests the behavior may not be treated as a standard security flaw that will be patched quickly.

The practical advice is simple. If you save important passwords in Edge, move them to a dedicated password manager and remove them from the browser after confirming the transfer. A dedicated password manager is generally a safer place for sensitive credentials because it is designed around stronger storage and access controls.

Here is what you should know:

IssueWhat it means
Passwords in RAMSaved Edge passwords may be readable in memory as plain text
Local access riskA malicious app or person with access to your PC could try to extract them
Browser authenticationEdge may still ask for authentication in settings, but RAM access can bypass that path
Microsoft’s reported positionThe behavior was described as intentional
Safer moveExport your passwords to a dedicated password manager, then delete them from Edge

This does not mean every Edge password has already been stolen. The risk depends on whether someone or some malware can access your device and read memory. Still, stored passwords are sensitive enough that this behavior deserves caution.

Until Microsoft changes how Edge handles saved credentials in memory, I would avoid using Edge as the main place to store passwords. Dedicated password managers are a better choice for anything important, especially banking, email, work, shopping, and social accounts.

Discover: News

Discussion (0)

Be the first to comment.