HomeSecurityMicrosoft Edge leaves passwords exposed in plain text

Microsoft Edge leaves passwords exposed in plain text

A Norwegian researcher, Tom Jøran Sønstebyseter Rønning, has identified a security flaw in Password Manager Microsoft Edge'sthat could pose a serious problem for businesses. The researcher discovered that passwords are stored within the browser in plain text, making any computer, especially a shared computer, within an organization a potential risk.

Microsoft Edge

In a post on X, Rønning explained that when users save passwords in Edge, the browser decrypts each credential on startup and keeps it in process memory, regardless of whether the user visits the website.

Independent tests by other researchers showed that indeed, even after closing and restarting the browser, the password could be found in plain text.

See also: CISA considers new 3-day deadline to remediate critical vulnerabilities

How is Microsoft addressing the issue in Microsoft Edge?

Microsoft appears to have been unconcerned about the discovery. Norwegian website Itavisen.no reported that “Rønning reported the issue to Microsoft, and according to the company, the behavior is ‘by design” Itavisen.no added that Rønning plans to publish a simple tool on GitHub that allows people to see for themselves that passwords are stored in plain text in memory.

David Shipley, CEO of Beauceron Security, was not impressed with Microsoft's response. "No, it's not a feature. It's an easy way to avoid responsibility. It's almost as bad as when companies say 'it works as designed.' The issue here, as with similar flaws, is convenience, speed, and avoiding investing more effort into something they don't think is worth mitigating," he said, stressing that the flaw in question is an open invitation for cybercriminals.

See also: Critical flaw in Apache HTTP/2 allows DoS and RCE

Fortunately, the problem has not been detected in other browsers. For example, Google Chrome offers a system called App Bound Encryption , which encrypts browser data and ensures that it is not stored in the process memory in plain text.

It's not an infallible system. It's been hacked in the past, but by determined hackers. The Microsoft bug, on the other hand, requires only a little skill to exploit.

Microsoft Edge leaves passwords exposed in plain text

Shipley said that if Google can do a better job of securing its browser, Microsoft can do the same with Edge.

"It's clearly not a technical hurdle. It's a motivation, which shouldn't surprise anyone because Microsoft is giving away the browser for free. You're not paying for it, so why would they care about securing it more than the bare minimum?" Given Microsoft's stance, users may want to look for another password manager, which would be more secure.

See also: Google offers up to $1.5 million for Android exploits

This revelation raises serious questions about how modern browsers handle sensitive data such as stored passwords. In an era where cybersecurity is a top priority for organizations and individuals, storing credentials in plain text in the system's memory significantly increases the risk of a breach, especially in corporate environments with shared or poorly secured workstations. Regardless of whether this behavior is considered "by design", its practical consequence creates an exploitable gap that cannot be ignored.

Microsoft Edge leaves passwords exposed in plain text

This incident highlights the importance of adopting stricter security standards by software providers, as well as conscious tool selection by users and businesses themselves. The use of specialized password managers with strong encryption, combined with multi-factor authentication and proper endpoint security policies, is now a necessary practice and not an optional choice. At the same time, such revelations serve as a reminder that ease of use should never override the protection of digital credentials.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS