Microsoft Edge Fixes Bug That Loaded Saved Passwords Into Memory at Startup
Key Takeaways Microsoft Edge has implemented a security enhancement to prevent saved passwords from being loaded into process memory at startup. This change is a defense-in-depth improvement, part of...
Key Takeaways
- Microsoft Edge has implemented a security enhancement to prevent saved passwords from being loaded into process memory at startup.
- This change is a defense-in-depth improvement, part of Microsoft’s Secure Future Initiative (SFI), and addresses a behavior identified by security researcher Tom Jøran Sønstebyseter Rønning.
- While Microsoft stated the previous behavior was not a new vulnerability and aligned with its threat model (requiring prior system compromise), it proactively reduced potential attack surfaces.
- The fix is rolling out automatically across all supported Edge channels, including Stable, Beta, Dev, and Extended Stable, with no user action required.
Microsoft Edge Bolsters Security by Limiting Password Exposure at Startup
Microsoft Edge is enhancing its security posture by altering how it handles saved user credentials. The browser will no longer automatically load stored passwords into process memory upon startup, a move aimed at further fortifying user data protection.
Table Of Content
This significant security improvement is a component of Microsoft’s overarching Secure Future Initiative (SFI), a strategic effort to integrate robust defense-in-depth measures across its diverse product ecosystem.
Addressing Researcher Findings
The update follows public disclosure by security researcher Tom Jøran Sønstebyseter Rønning, who identified that Microsoft Edge was loading saved passwords into memory in clear text during the browser’s initialization phase.
Microsoft acknowledged Rønning’s discovery but clarified that the observed behavior conformed to its established threat model and did not introduce a novel security vulnerability. The company explained that the scenario described by the researcher presupposes an attacker has already gained control over the victim’s device.
In situations where malicious code can execute locally with elevated privileges, browsers and other applications generally cannot prevent access to credentials. This limitation is not unique to Edge; it is a consistent characteristic across modern browsers and typically falls outside the purview of standard browser threat models.
Proactive Defense-in-Depth Enhancement
Despite the behavior aligning with its threat model, Microsoft emphasized its commitment to minimizing the unnecessary exposure of sensitive data. Consequently, the company has implemented a defense-in-depth improvement specifically to prevent passwords from being loaded into memory during the startup sequence.
“This change is a proactive step to minimize potential attack surfaces, even in scenarios that fall outside our defined security boundaries,” Microsoft stated, highlighting its commitment to continuous security enhancement.
The fix has already been integrated into Edge Canary builds and is being progressively deployed across all supported versions, encompassing Stable, Beta, Dev, and Extended Stable channels. The Microsoft Edge 148 update will install automatically, requiring no user intervention.
Microsoft reassured its user base that the previously reported behavior did not introduce new exposure or elevate existing risks. The company reiterated that access to in-memory credentials would only be feasible if an attacker had already achieved an advanced stage of system compromise, extending beyond typical browser-level protections.
Broader Security Investments and Community Engagement
Beyond this specific change, Microsoft underscored its ongoing investment in multi-layered security mechanisms. These include advanced sandboxing technologies, renderer isolation, and proactive defenses such as the Scareware Blocker, designed to shield users from malicious websites.
The company also recognized the invaluable contributions of the security research community and indicated it is actively reviewing its internal processes for handling vulnerability reports. Microsoft aims to enhance response speed, improve communication clarity, and integrate defense-in-depth considerations earlier into its vulnerability evaluation pipeline.
This strategic move aligns with a broader industry imperative to harden software against sophisticated, multi-stage cyberattacks. By restricting how and when sensitive data like passwords are exposed in memory, Microsoft Edge endeavors to mitigate the risk of credential theft, even in complex, edge-case scenarios.
What You Should Do
- Ensure your Microsoft Edge browser is updated to the latest version (148 or newer). Updates typically install automatically, but you can manually check for updates via Edge Settings > About Microsoft Edge.
- Continue to use a strong, unique password for your Microsoft account and enable multi-factor authentication (MFA) for an additional layer of security.
- Employ a reputable antivirus/anti-malware solution and keep your operating system updated to protect against broader system compromises that could bypass browser-level protections.
- Be vigilant against phishing attempts and social engineering tactics, as these remain primary vectors for initial system access.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.