CriticalSecurity & Privacy
Microsoft Edge stores all passwords in memory in clear text, even when unused
Microsoft Edge has a critical security vulnerability where passwords are stored in memory in clear text, creating significant exposure to credential theft even when passwords are not actively being used. This finding has major implications for enterprise security posture, requiring IT organizations to reassess Edge deployment in sensitive environments and evaluate compensating controls or alternative browsers. Organizations relying on Edge for authenticated access to critical systems face increased risk of lateral movement and unauthorized access if systems are compromised.
Hacker News3 min read

Microsoft Edge has a critical security vulnerability where passwords are stored in memory in clear text, creating significant exposure to credential theft even when passwords are not actively being used. This finding has major implications for enterprise security posture, requiring IT organizations to reassess Edge deployment in sensitive environments and evaluate compensating controls or alternative browsers. Organizations relying on Edge for authenticated access to critical systems face increased risk of lateral movement and unauthorized access if systems are compromised.