Security researcher Tom Jøran Sønstebyseter Rønning disclosed that Microsoft Edge loads saved credentials from its built-in Microsoft Password Manager into process memory in plaintext, allowing them to be recovered from memory dumps even when the related websites are not open. Rønning demonstrated the issue publicly and released the EdgeSavedPasswordsDumper proof-of-concept on GitHub, while independent reporting and reproduction showed credentials appearing in readable form alongside site URLs, usernames, and passwords. Microsoft reportedly said the behavior is by design rather than a vulnerability, arguing that exploitation already requires a compromised system or an attacker with sufficient privileges to read browser memory.
The disclosure has raised particular concern for enterprise Windows environments including Citrix, VDI, and terminal servers, where administrators or attackers with elevated access could scrape passwords from other logged-in users’ Edge processes and use them for impersonation, lateral movement, fraud, or ransomware operations. Researchers said Edge was the only Chromium-based browser they tested that kept all saved credentials decrypted in memory at startup, contrasting it with browsers such as Chrome and Brave, which decrypt credentials only when needed and use stronger protections such as app-bound encryption. Recommended mitigations include disabling password storage in Edge through policy, reducing browser-based credential storage, limiting administrative privileges, monitoring for memory-scraping activity, and moving users to dedicated password managers.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft reportedly acknowledged the browser behavior and said it is expected functionality rather than a bug, framing it as a performance-versus-security tradeoff and arguing that successful memory scraping already implies a severely compromised system. Security experts criticized this stance as poor security design because it leaves credentials exposed in cleartext memory.
A proof-of-concept tool named EdgeSavedPasswordsDumper was released on GitHub to demonstrate extraction of saved Edge credentials from process memory. The repository stated the tool could read same-user Edge memory without admin rights and other users' Edge processes with administrator privileges on the same machine.
Rønning publicly demonstrated the behavior at Palo Alto Networks Norway's BIG Bite of Tech conference in Oslo, and separate reporting showed the issue could be reproduced by dumping Edge process memory and searching it for credentials. The demonstrations showed saved site URLs, usernames, and passwords could be recovered from memory.
Security researcher Tom Jøran Sønstebyseter Rønning found that Microsoft Edge loads saved credentials from its built-in password manager into browser process memory in plaintext, unlike other tested Chromium-based browsers that decrypt credentials only when needed. The issue was highlighted as especially risky on shared Windows environments such as Citrix, VDI, and terminal servers.
Tom Jøran Sønstebyseter Rønning publicly disclosed that Microsoft Edge decrypts all saved passwords at startup and keeps them in process memory in cleartext, unlike other tested Chromium-based browsers. He warned the behavior is especially risky on shared Windows, terminal server, and VDI environments where attackers could scrape credentials from Edge processes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcescworld.com
Open sourcehackread.com
Open sourcezdnet.fr
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourcedarkreading.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.