TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Digital Trends

Microsoft Edge has a serious password problem, and Microsoft says it is working as intended

Manisha Priyadarshini · 10 hours ago · Read original ↗

ATT&CK techniques detected

2 predictions
T1555.003Credentials from Web Browsers
91%
“to pull passwords out of memory. but microsoft edge does neither. rønning tested multiple chromium - based browsers and found that edge was the only one that loaded all saved passwords into memory at startup and left them out there in cleartext. what does microsoft say, and shoul…”
T1555.003Credentials from Web Browsers
78%
“microsoft edge has a serious password problem, and microsoft says it is working as intended if you save your passwords in microsoft edge, here ’ s something you should know. every time you open the browser, it decrypts all your saved passwords and loads them into memory in cleart…”

Summary

A security researcher found that Microsoft Edge loads all saved passwords into unencrypted memory at startup, keeping them exposed for the entire session even when they are not in use.