Hacker News
Microsoft Edge Stores Every Saved Password in Cleartext Memory at Launch — Microsoft Says 'By Design' — 555 Points on HN
Security researcher @L1v1ng0ffTh3L4N discovered that Microsoft Edge decrypts every stored password into process memory as cleartext the moment the browser launches, regardless of whether those sites are visited. Unlike Chrome, which uses on-demand decryption, Edge loads the entire vault into plaintext and retains it for the session. In a published PoC, a compromised admin extracts credentials from two other logged-on users with Edge running — even from disconnected sessions. Microsoft's official response: the behavior is 'by design.' Maps to MITRE ATT&CK T1555.003.
Source
↳ Follow the thread