Hacker News.

When you save passwords in Edge, the browser decrypts every credential at startup and keeps them resident in process memory. This happens even if you never visit a site that uses those credentials.

At the same time, Edge requires you to re‑authenticate before showing those same passwords in the Password Manager UI — yet the browser process already has them all in plaintext.

Edge is the only Chromium‑based browser I’ve tested that behaves this way. By contrast, Chrome uses a design that makes it far harder for attackers to extract saved passwords by simply reading process memory.

It decrypts credentials only when needed, instead of keeping all passwords in memory at all times. App‑Bound Encryption (ABE) adds another layer by binding decryption to an authenticated Chrome process, preventing other processes from reusing Chrome’s encryption keys.

Because of these controls, plaintext passwords appear only briefly during autofill or when the user views them, making broad memory scraping far less effective. The risk of keeping the passwords in cleartext in memory becomes evident in shared environments.

If an attacker gains administrative access on a terminal server, they can access the memory of all logged‑on user processes. In the video the attacker has compromised a user account with administrative rights and is able to view stored credentials for two other logged on

(or even disconnected) users with Edge running. I reported this to Microsoft, and the official response was that the behavior is "by design". They have been informed that I would be sharing this as a responsible disclosure so users and organizations can make informed decisions

about how they manage credentials. Last wednesday (April 29th) I disclosed this on BigBiteOfTech by Norway

Simple, educational proof of concept, to show that the passwords are stored in cleartext in memory.

Source.

If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security.

~Satya Nadella, Microsoft Chairman and CEO, May 3, 2024

https://blogs.microsoft.com/blog/2024/05/03/prioritizing-security-above-all-else/

So much for that I guess.

4 replies

Thoughts on Darktrace or MS Sentinel?

14h 41m ago by reddthat.com/u/Lemmert in cybersecurity@infosec.pub
342

Mentorship Monday - Discussions for career and learning!

1d 8m ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
303

Vulnerability Report - April 2026

22h 28m ago by literature.cafe/u/cm0002 in cybersecurity@infosec.pub from www.vulnerability-lookup.org
204

Hackers are actively exploiting a bug in cPanel, used by millions of websites

4d 10h ago by literature.cafe/u/cm0002 in cybersecurity@infosec.pub from techcrunch.com
1815

The most severe Linux threat to surface in years catches the world flat-footed

4d 9h ago by discuss.tchncs.de/u/schnurrito in cybersecurity@infosec.pub from arstechnica.com
1876

Celebrity Stalkerware Data Breach: 86K+ Private Images Leaked

3d 15h ago by mander.xyz/u/Deep in cybersecurity@infosec.pub from www.expressvpn.com
807

Off-Topic Friday

3d 18h ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
508

Copy Fail — 732 Bytes to Root

4d 23h ago by literature.cafe/u/cm0002 in cybersecurity@infosec.pub from copy.fail
1309

Vimeo suffers 3rd-party breach exposing user data, hackers threaten leak

6d 3h ago by mander.xyz/u/Deep in cybersecurity@infosec.pub from cyberinsider.com
20010

What are You Working on Wednesday

6d 13m ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
4111

Mentorship Monday - Discussions for career and learning!

7d 18h ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
3013

Off-Topic Friday

11d 50m ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
7214

Chinese attackers are pwning your infrastructure to use in attacks, 10 countries warn

11d 7h ago by mander.xyz/u/Sepia in cybersecurity@infosec.pub from www.theregister.com
14115

PLC Cybersecurity — Securing Industrial Control Systems

11d 8h ago by lemmy.world/u/monica_b1998 in cybersecurity@infosec.pub from slicker.me
11016

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Attack

11d 11h ago by libretechni.ca/u/cm0002 in cybersecurity@infosec.pub from socket.dev
48017

What are You Working on Wednesday

12d 22h ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
7118

Iran claims US exploited networking equipment backdoors during strikes

13d 26m ago by lemmy.ca/u/floofloof in cybersecurity@infosec.pub from www.tomshardware.com
49119

Iran, Russia and China behind most major cyberattacks on UK, security chief warns

13d 1h ago by scribe.disroot.org/u/randomname in cybersecurity@infosec.pub from www.the-independent.com
12020

Wireshark tutorial: Capture vs. Display Filters

13d 9h ago by lemmy.world/u/monica_b1998 in cybersecurity@infosec.pub from slicker.me
7121

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

13d 18h ago by libretechni.ca/u/cm0002 in cybersecurity@infosec.pub from words.filippo.io
10122

FakeWallet cryptostealer propagating via iOS App Store applications

14d 3h ago by piefed.world/u/beep in cybersecurity@infosec.pub from securelist.com
6023

Microsoft's Silent Lockout: Why WireGuard, VeraCrypt & Windscribe Can No Longer Update Windows Users

15d 16h ago by libretechni.ca/u/cm0002 in cybersecurity@infosec.pub from techlore.tech
70824

HTTP desync in Discord's media proxy: Spying on a whole platform

16d 19h ago by piefed.world/u/beep in cybersecurity@infosec.pub from tmctmt.com
9025

NIST gives up enriching most CVEs

16d 19h ago by piefed.world/u/beep in cybersecurity@infosec.pub from risky.biz
7026

Claude Opus wrote a Chrome exploit for $2,283

17d 9h ago by lemdro.id/u/cm0002 in cybersecurity@infosec.pub from www.theregister.com
13127

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

17d 19h ago by lemmy.world/u/monica_b1998 in cybersecurity@infosec.pub from thehackernews.com
81028

Off-Topic Friday

17d 22h ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
5029

108 Chrome extensions caught stealing user data and hijacking sessions

18d 4h ago by piefed.world/u/beep in cybersecurity@infosec.pub from socket.dev
10030

Fiverr left customer files public and searchable on Google

18d 4h ago by piefed.world/u/beep in cybersecurity@infosec.pub from news.ycombinator.com
6031

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

21d 10h ago by lemmings.world/u/cm0002 in cybersecurity@infosec.pub from anchor.host
35233

AI Cybersecurity After Mythos: The Jagged Frontier

23d 17h ago by lemmings.world/u/cm0002 in cybersecurity@infosec.pub from aisle.com
4034

Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise

23d 17h ago by lemmings.world/u/cm0002 in cybersecurity@infosec.pub from www.theregister.com
18235

HWMonitor & CPU-Z users were exposed to malware through fake downloads after CPUID breach

23d 21h ago by lemmings.world/u/cm0002 in cybersecurity@infosec.pub from alternativeto.net
6036

Supply chain nightmare: How Rust will be attacked and what we can do to mitigate the inevitable

23d 21h ago by lemmings.world/u/cm0002 in cybersecurity@infosec.pub from kerkour.com
13037

CPUID site hijacked to serve malware instead of HWMonitor downloads

24d 9h ago by infosec.pub/u/cm0002 in cybersecurity@infosec.pub from www.theregister.com
942839

ur best techno-babble to bypass clueless auditors?

24d 15h ago by thelemmy.club/u/astrobird in cybersecurity@infosec.pub from dev.to
5041

CPUID hijacked to serve malware as HWMonitor downloads

24d 20h ago by infosec.pub/u/Deebster in cybersecurity@infosec.pub from www.theregister.com
22042

FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database

24d 23h ago by infosec.pub/u/cm0002 in cybersecurity@infosec.pub from www.404media.co
59943

Microsoft BANNED WireGuard, VeraCrypt & Windscribe With Zero Warning

25d 22h ago by infosec.pub/u/cm0002 in cybersecurity@infosec.pub from www.youtube.com
12544

Vulnerability-Lookup 4.4.0

25d 22h ago by infosec.pub/u/cm0002 in cybersecurity@infosec.pub from github.com
5045

What are You Working on Wednesday

27d 14m ago by infosec.pub/u/shellsharks in cybersecurity@infosec.pub
3146

Adobe modifies hosts file to detect whether Creative Cloud is installed

28d 19h ago by lemmy.ca/u/floofloof in cybersecurity@infosec.pub from www.osnews.com
1001047

New multilingual severity classifiers for vulnerability analysis

28d 21h ago by lemy.lol/u/cm0002 in cybersecurity@infosec.pub from www.vulnerability-lookup.org
2048

CNVD Severity Classification and RMSV Effects: Honest Metrics & Data Leakage

1mon 2d ago by lemmings.world/u/cm0002 in cybersecurity@infosec.pub from www.vulnerability-lookup.org
2049

Supply chain attack hits 300 million-download Axios npm package

1mon 4d ago by toast.ooo/u/cm0002 in cybersecurity@infosec.pub from www.itnews.com.au
16050