The Edge browser stores all passwords in plain text
Passwords are stored directly in RAM, which is not secure.
Security researcher Tom Jøran reported that Microsoft Edge stores all saved passwords in clear text, directly in the computer’s RAM, even when they are not in use.
He clearly demonstrated that Edge decrypts passwords when the browser is launched and stores them in the process memory, from where they can be read without password authorization or via Windows Hello, even though authorization is requested when trying to access the password manager.
Only the Edge browser does this – Chrome uses ABE encryption and does not store passwords in memory.
The Edge browser allows attackers to easily access passwords. A video shows how a hacked Windows administrator account can view all the passwords of other users on the computer. Microsoft was contacted, and they responded that this is normal behavior for the browser.
Image:


