Microsoft Edge passwords will soon receive stronger protection after Microsoft confirmed a major change to how the browser handles saved login details. The company plans to stop Edge from loading stored passwords into process memory in clear text when the browser starts.

The decision follows criticism from security researchers, who warned that the previous behavior created unnecessary exposure. Microsoft first described the issue as “by design,” but it has now changed course and will roll out a defense-in-depth improvement across supported Edge versions.

Researcher Found Passwords Loaded at Startup

Security researcher Tom Jøran Sønstebyseter Rønning disclosed the issue on May 4. He said Edge decrypted all saved credentials when the browser launched and kept them in memory, even when users did not visit the related websites.

That behavior made Microsoft Edge different from some other Chromium-based browsers. According to the researcher, Chrome decrypts credentials only when needed, which makes broad memory scraping harder for attackers.

Rønning also released a proof-of-concept tool that showed how attackers could dump saved credentials from Edge processes. With administrator privileges, an attacker could target other users’ Edge processes. Without admin rights, the tool could access Edge processes running under the same user account.

Why the Issue Raised Concern

The risk matters because many modern cyberattacks focus on credential theft. Infostealer malware often targets browsers, session data, and saved login details after gaining access to a device.

Microsoft argued that the scenario already required a compromised system. However, security researchers pushed back against that view. They argued that browsers should still reduce sensitive data exposure wherever possible, especially in business environments.

Shared systems, remote desktops, and enterprise workstations could face higher risks. If attackers gain strong local access, cleartext passwords in memory can increase the damage from a single compromised machine.

Microsoft Reverses Its Position

Microsoft initially said the behavior was expected and did not fall outside its threat model. However, the company has now confirmed that Edge will stop loading saved passwords into memory at startup.

Gareth Evans, Microsoft Edge Security Lead, said the change reflects a broader security approach under Microsoft’s Secure Future Initiative. Instead of focusing only on strict vulnerability definitions, Microsoft will also look for ways to reduce unnecessary exposure.

The fix is already live in Edge Canary. Microsoft plans to bring it to all supported Edge channels, including Stable, Beta, Dev, Canary, and Extended Stable enterprise releases, starting with build 148 and newer.

What Users Should Do Now

Users should keep Microsoft Edge updated as the fix reaches broader release channels. Businesses should also review browser password policies, especially in shared or high-risk environments.

A dedicated password manager may offer stronger controls for users who manage many sensitive accounts. Multi-factor authentication also remains important, since stolen passwords alone should not give attackers full access.

Conclusion

The Microsoft Edge passwords update shows how security pressure can lead to practical product changes. Microsoft may not classify the original behavior as a traditional vulnerability, but reducing cleartext password exposure still improves protection.

The change will not stop every credential theft attack. However, it should make Edge a safer option for users who rely on its built-in password manager.


0 responses to “Microsoft Edge Passwords Will Get Safer After Update”