Microsoft is changing how Microsoft Edge handles saved passwords in version 148. The update stops the browser from loading all stored passwords into random access memory in cleartext when the application starts. This modification addresses a specific security vulnerability that existed in previous builds.
Browser update addresses security vulnerability in password memory handling
Prior to this change, Edge decrypted every saved password and loaded it into memory immediately upon launch. A Norwegian security researcher named Tom Jøran Sønstebyseter Rønning identified this behavior during his testing. He found that Edge was the only browser among those he tested that kept all passwords in plaintext simultaneously.

Microsoft initially defended the design choice but reversed course after facing public backlash and security concerns. The company acknowledged the risk and implemented the fix to prevent unauthorized access to credentials stored in memory. Other Chromium-based browsers do not exhibit this specific plaintext storage behavior at startup.
The update applies to Microsoft Edge version 148 and represents a significant shift in the browser's security architecture. The change aims to protect user data from potential memory scraping attacks. Microsoft has not confirmed the exact launch window for the general public release.
Source: TweakTown




Discussion
0 comments