Forum Overview :: Descent: AI Droid
 
Passwords in Edge stored in plaintest by MicroSLOP 05/04/2026, 8:35pm PDT
Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."

All of them. Including credentials for sites you won't open this session.

Researcher
@L1v1ng0ffTh3L4N
tested every major Chromium browser. Edge is the only one that behaves this way.

Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.

In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.

What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.

In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.

Microsoft's official response when notified: "by design."

The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.


The DESIGN could use a little Craft & Focus
PREVIOUS REPLY QUOTE
 
Copilot devs: Assholes by Rafiki 12/17/2025, 9:00am PST NEW
    SLOP SLOP SLOP by SLOP SLOP SLOP 12/17/2025, 5:24pm PST NEW
    In a way, it's all your fault, if you think about it. by Microsoft dev 12/17/2025, 5:27pm PST NEW
    Welcome to the futur NT by Fuckerberg’s amazing slop machine 12/18/2025, 10:22pm PST NEW
    Everytime Microsoft has a problem that could have been solved by qa by MicroSLOP 04/10/2026, 11:51am PDT NEW
        They made Github unusable by MicroSLOP 04/27/2026, 10:13pm PDT NEW
        Passwords in Edge stored in plaintest by MicroSLOP 05/04/2026, 8:35pm PDT NEW
 
powered by pointy