A security researcher says Microsoft Edge stores passwords in plaintext in system memory (RAM), allowing them to be recovered through memory dumping. The finding is based on experiments using Edge’s built-in password manager: after saving a password and completing the verification step, the researcher reports that the browser loads plaintext password data into RAM and that passwords can be extracted by examining memory.
The researcher also compares Edge’s behavior with Google Chrome. According to the report, Chrome only loads the password for the specific website being authenticated when challenged, and it removes the password from memory after filling it. In contrast, Edge is described as keeping password data available in memory beyond use.
Microsoft responds by downplaying the risk, stating that accessing browser data as described would require an already compromised device, such as malware with sufficient control. Microsoft also says it reviews design choices against changing threats and reiterates that browsers use memory to sign in quickly and securely. The company recommends installing security updates and using antivirus protection.