Edge's Hidden Risk: Every Saved Password Is Fully Exposed in Memory
A security researcher has uncovered a significant vulnerability in Microsoft Edge where the browser automatically decrypts and stores all saved login credentials in cleartext within the system's process memory as soon as the application is launched. Unlike other browsers that may decrypt passwords only when needed, Edge maintains these credentials in an unencrypted state regardless of whether the user visits the associated websites or interacts with the password manager. This behavior potentially allows malicious actors or specialized malware with access to system memory to harvest sensitive login data with ease, highlighting a major oversight in the browser's data protection architecture.