Microsoft Edge will load all your passwords into memory in plain text, but Microsoft says it’s not a security issue


Microsoft Edge It has been found to store all passwords in plain text when loaded into memory at startup, making passwords much easier to read and extract by malware or hackers. cybersecurity researcher @L1v1ng0ffTh3L4N posted about the exploit in X, and says “Edge is the only Chromium-based browser I’ve tested that behaves this way.”

“When you save passwords in Edge, the browser decrypts each credential at startup and keeps them resident in process memory. This happens even if you never visit a site that uses those credentials.” says the security researcher. “If an attacker gains administrative access on a terminal server, they can access the memory of all logged-in user processes.”





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *