What Microsoft is changing and why for saved passwords in Microsoft Edge memory



 Microsoft Browser Vulnerability Research:

Browsers help protect some of the most sensitive data people have, including passwords. That’s why we continuously review how Edge handles that data, and where we can further reduce exposure through defense-in-depth improvements as part of Microsoft’s Secure Future Initiative (SFI).

Last week, a security researcher publicly disclosed that Edge loads saved passwords into process memory in cleartext at startup. Based on our existing criteria, this behavior falls within the expected threat model, since the risk begins after an attacker has already compromised the device. At the same time, we believe there’s opportunity to improve. In this blog, we’ll show you what we’re changing and why.

We’re addressing the originally reported issue immediately​

We will no longer load passwords into memory on startup. This defense-in-depth change will come to every supported version of Edge (Stable, Beta, Dev, Canary, and the Extended Stable channel our enterprise customers run), and we’re prioritizing the rollout. The change is live now in Edge Canary and included in the next update for all Edge releases, build 148 and newer.

If you use Edge’s password manager today, you don’t need to take any action. The change will reach you through the normal update channel.

Why there is no new customer exposure​

We care deeply about the trust customers place in Edge, especially when it comes to protecting sensitive data like passwords. Your first question and our first investigation is the same: ‘Does this mean I’m exposed?’

In this case, the answer is no.

This is because the reported scenario requires an attacker who already has control of the user’s device. Once the attacker can run unsafe software locally as admin, the situation is beyond the defenses of the browser (or any application). The threat model for our password manager is explicit that physically local attacks and malware running with elevated privileges are out of scope, and that’s consistent with every modern browser.

In other words, the report does not raise a new avenue for attackers to access credentials through the browser itself.

Our commitment to defense-in-depth​

Even for issues that don’t meet the security criteria, Edge invests heavily in defense-in-depth. We run sophisticated sandboxes, we isolate renderers, and we work hard to break attack chains even within a single privilege boundary, because real-world attacks are almost never a single clean step. We have proactive defenses like Scareware blocker to protect users from sites acting in bad faith.

With our commitment to the Secure Future Initiative and customer feedback, we are taking a broader view. That means looking not only at whether something meets the bar for a security issue, but also at where we can reduce exposure through defense-in-depth improvements. In this case, reducing the exposure of passwords in memory is a practical step in that direction.

Report handling in the future​

Keeping customers safe requires not just strong defenses, but strong processes. Our initial response was based on the shared security criteria for the Chromium project. That’s a baseline and we hold ourselves to a higher bar. So we’re reviewing how we handle researcher reports, with a focus on speed, clarity, and applying defense-in-depth thinking earlier. We’ll share what we’ve learned, along with the improvements we’re making.

We thank the security research community for raising concerns. We take your reports seriously and remain focused on earning and keeping our customers’ trust.



 Source:

 
That mealy mouth description appears to really be easily translated. 🤣

"We screwed up, and we're changing things to remove the obviously insecure design!"
 

My Computers

System One System Two

  • OS
    Win 11 Pro 25H2, Build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Operating System
    Win 11 Pro 25H2, Build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
That mealy mouth description appears to really be easily translated. 🤣

"We screwed up, and we're changing things to remove the obviously insecure design!"
exactly

At the same time, we believe there’s opportunity to improve. In this blog, we’ll show you what we’re changing and why.

Yeah they only came to this conclusion after multiple articles were made about them not fixing it. It wasn't until a stink was made about it that they cared.

We care deeply about the trust customers place in Edge, especially when it comes to protecting sensitive data like passwords.

If you did, you would not be the only browser to have this issue, and then ignore it when it was reported. 🤷‍♂️

Getting admin access on windows is so trivial, so while sure having a machine compromised is a problem of course, why make it easier? The goal of security is to reduce the attack surface. Everything about security is time based, the longer and more annoying it is that slows them down even slightly is worth it compared to having nothing at all.

It like saying the security guard was shot outside and is dead, so we won't bother locking the doors to the building. Because it doesn't matter, they will get in eventually.

That is not the way to approach security and I question microsoft for ever thinking that was an acceptable answer.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    4TB Western Digital nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Keyboard
    Logitech G213
    Mouse
    Logitech G203
    Internet Speed
    1.2gbps Fiber 😎
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
Maybe the MS employees forgot the executive memo from Satya:

Prioritizing security above all else - The Official Microsoft Blog
If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security. In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems. This is key to advancing both our platform quality and capability such that we can protect the digital estates of our customers and build a safer world for all.

Satya
 

My Computer

System One

  • OS
    Windows 7
Back
Top Bottom