Microsoft Edge Stores Your Entire Password Vault in Cleartext Process Memory — Every Session
Security researcher @L1v1ng0ffTh3L4N has revealed that Microsoft Edge decrypts all stored passwords into plaintext process memory at browser launch and keeps them there for the entire session. Unlike Chrome, Edge lacks on-demand decryption and App-Bound Encryption, creating serious credential exposure risks especially in RDS and VDI environments. Microsoft says the behavior is ‘by design.’
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.