Discover top-rated products handpicked for quality, style, and unbeatable value — only at StellarFindsHub

Microsoft Edge Security Issue: Passwords Are Stored In Plaintext RAM

A recent cybersecurity investigation has revealed a significant concern regarding how Microsoft Edge handles user credentials. The findings, shared by researcher Tom Jøran Sønstebyseter Rønning, indicate that the browser stores saved passwords in plaintext—meaning they are unencrypted and readable—within the system’s RAM while the application is active.

Unlike many modern browsers that decrypt credentials only at the moment of use, Microsoft Edge appears to keep all stored passwords accessible in the system memory for the duration of the browser session. This behavior persists as long as the application is running, regardless of whether the user is actively accessing their password manager or logging into a website.

The primary risk associated with this behavior involves local security. If an unauthorized individual gains physical access to a machine or manages to obtain administrative privileges remotely, they could potentially extract sensitive login information directly from the RAM. Rønning demonstrated this by posting a proof-of-concept tool on GitHub, which illustrates how easily these data strings can be retrieved in a legible format.

The investigation highlights a significant departure from the security protocols used by other Chromium-based browsers. Google Chrome, for instance, typically decrypts credentials only when necessary and clears them from the memory shortly thereafter to minimize the “window of exposure.” Microsoft Edge’s architecture, however, maintains this data in an unencrypted state continuously throughout the session.

Microsoft’s Response and Design Philosophy

Despite the criticism from the cybersecurity community, Microsoft has acknowledged the behavior but maintains that it is not a software bug. Instead, the company has characterized this as an intentional design decision. As of yet, Microsoft has not provided a specific technical justification for why keeping sensitive credentials permanently accessible in the memory serves a practical advantage for the user.

For users who rely on Microsoft Edge as their primary password manager, these revelations raise significant questions regarding local privacy and data protection. Security experts suggest using dedicated third-party password managers or ensuring that browsers are fully closed when not in use to mitigate such risks.

Trending Products

- 31% ASUS RT-AX1800S Twin Band WiFi 6 Ex...
Original price was: $99.99.Current price is: $68.94.

ASUS RT-AX1800S Twin Band WiFi 6 Ex...

0
Add to compare
0
Add to compare
- 18% TP-Link AX5400 WiFi 6 Router (Arche...
Original price was: $169.99.Current price is: $139.99.

TP-Link AX5400 WiFi 6 Router (Arche...

0
Add to compare
- 27% MSI MPG GUNGNIR 110R – Premiu...
Original price was: $109.99.Current price is: $79.99.

MSI MPG GUNGNIR 110R – Premiu...

0
Add to compare
- 12% Lenovo 15.6″ FHD Laptop, Inte...
Original price was: $429.00.Current price is: $378.99.

Lenovo 15.6″ FHD Laptop, Inte...

0
Add to compare
- 5% GAMDIAS ATX Mid Tower Gaming Laptop...
Original price was: $59.99.Current price is: $57.20.

GAMDIAS ATX Mid Tower Gaming Laptop...

0
Add to compare
0
Add to compare
- 20% SAMSUNG 27″ T35F Sequence FHD...
Original price was: $149.99.Current price is: $119.99.

SAMSUNG 27″ T35F Sequence FHD...

0
Add to compare
- 25% cimetech EasyTyping KF10 Wi-fi Keyb...
Original price was: $39.99.Current price is: $29.99.

cimetech EasyTyping KF10 Wi-fi Keyb...

0
Add to compare
- 28% Wi-fi Keyboard and Mouse Combo, MAR...
Original price was: $28.99.Current price is: $20.99.

Wi-fi Keyboard and Mouse Combo, MAR...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

StellarFindsHub
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart