
Microsoft Edge to Stop Loading Cleartext Passwords in Memory on Startup
MicrosoftSecurity
Microsoft is updating the Edge web browser to prevent it from loading saved passwords into process memory in cleartext during startup, reversing its prior stance that this behavior was "by design." The change addresses a security concern where passwords stored in Edge could be exposed in memory without encryption. No specific timeline, CVE ID, or technical implementation details were provided in the update. The modification follows criticism of the initial design choice, which posed risks of credential theft via memory-scraping attacks. The update applies to all versions of Microsoft Edge where this behavior was present.