VulnerabilitiesMay 5, 2026
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
Microsoft Edge stores passwords in process memory, enabling theft via admin access.
Vendor Watch
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
A proof-of-concept exploit demonstrates that Microsoft Edge stores user passwords in process memory, allowing an attacker with administrative privileges to extract and steal them. The vulnerability poses a significant risk to enterprise environments where password security is critical. The flaw enables lateral movement and further malicious activity once credentials are compromised.
Indicators of Compromise
- malware — Edge memory password extractor (PoC)
Entities
Microsoft Edge (product)Microsoft (vendor)Process Memory (technology)