UPDATE An attacker with administrative privileges can gain access to Microsoft Edge user passwords even when they're not in use, because the browser stores them in cleartext in process memory as part of a design decision by Microsoft. Security researcher Tom Jøran Sønstebyseter Rønning revealed the issue and how it can be exploited in a proof-of-concept (PoC) tool at Palo Alto Networks Norway's BIG Bite of Tech conference last week. He subsequently posted resources for the PoC and tool on GitHub. The basic issue is that Microsoft Edge decrypts and stores all passwords that have been saved in the browser in process memory, "even if the person never visits the site that uses those credentials," Rønning, offensive security/internal penetration tester and technical team lead of proactive security at Norway's Statnett SF, wrote on X in one of a series of posts detailing the issue. He conducted the research about the issue in his own time and not in his role at the company, he noted. This sets up an extremely risky scenario, especially for shared corporate environments, he said, because an attacker who gains admin access on a terminal service "can access the memory of all logged‑on user processes," Rønning wrote. Speaking to Dark Reading by phone, Rønning explained how an attacker with administrative access can exploit the issue in an organization running a Windows environment by accessing process memory via Citrix, virtual desktop infrastructure (VDI), or a Windows terminal server...
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
Dark Reading
·Elizabeth Montalbano
·Published May 5, 2026
·Updated
Affected Software
1 affected component
Microsoft Edge
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in Microsoft Edge where passwords are stored in cleartext in process memory.
2
What security implications are discussed?
The article highlights that an attacker with administrative privileges can access user passwords stored in Microsoft Edge, posing a significant risk for enterprises.
3
What products or software are affected?
The affected software mentioned in the article is Microsoft Edge.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by obtaining administrative privileges on a system running Microsoft Edge.
5
What does storing passwords in cleartext mean for users?
Storing passwords in cleartext means that they are not encrypted and can be easily read by anyone with access to the process memory.