Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Microsoft Edge’s built-in password manager loaded all saved credentials into process memory in cleartext at browser startup, exposing them to any process running under the same user account or with administrative privileges. Microsoft initially defended the behavior as intentional before reversing course and committing to a fix beginning with build 148. The incident raises a pointed question for security leaders: browser-native credential storage has been marketed as a convenience feature, but this case demonstrates that it can introduce credential exposure risk equivalent to storing passwords in a plaintext file. Notably, no CVE identifier has been assigned to this exposure, suggesting Microsoft’s handling prioritized rapid fix deployment over formal vulnerability tracking.

Author

Tech Jacks Solutions