Microsoft Edge saves passwords in cleartext ‘by design’ and researchers argue ’this turns into a credential harvest’ on shared PCs
Microsoft Edge has been found to store all user passwords in plaintext in memory upon startup, according to security researcher Tom Jøran Sønstebyseter Rønning. This means passwords remain easily accessible to anyone with admin-level access to a shared computer, creating a significant security risk on multi-user systems.
The researcher tested Edge against other Chromium-based browsers and found it to be the only one exhibiting this behavior. When credentials are saved in Edge, the browser decrypts every password at startup and keeps them resident in process memory, leaving them vulnerable to being scraped by malware or accessed by users with sufficient permissions.
When Rønning reported this finding to Microsoft, the company responded that this behavior is “by design” and not a security concern. However, researchers argue that on shared PCs—where multiple users may have admin access—this creates a “credential harvest” scenario, as passwords remain easily accessible throughout the browsing session. While the vulnerability requires admin-level permissions to exploit, it highlights a potential weakness in Edge’s password management compared to other browsers.