Microsoft backpedals: Edge to stop loading passwords into memory
Patch: Upgrade all Edge installations to build 148 or newer to stop passwords from loading into memory at startup.
Patch: Update Edge to build 148 or newer on all devices, verify that passwords no longer appear in process memory, and audit for any residual memory exposure.
Summary
Microsoft Edge previously loaded all saved passwords into process memory at startup, a design that a researcher demonstrated could be exploited by administrators to dump credentials from other users’ Edge processes. The PoC, released on May 4, showed that the decrypted passwords remained in memory even when not in use, exposing them to memory‑dump attacks. Microsoft initially dismissed the issue as “by design,” but after public disclosure, the company announced that future Edge releases will no longer load passwords into memory on startup. The fix is already live in the Edge Canary channel and will ship in the next update for all supported channels (Stable, Beta, Dev, Canary, and Extended Stable) with build 148 or newer. The change reduces exposure for users with administrative privileges and aligns with Microsoft’s Secure Future Initiative. Microsoft has also added a security feature to protect against malicious extensions and restricted Internet Explorer mode after zero‑day exploits in the Chakra engine. The update addresses a threat model that excludes attacks where an adversary already has admin control. The change applies to all supported Edge releases, ensuring that passwords are no longer present in process memory at launch.
Key changes
- Edge will no longer load saved passwords into process memory on startup for all supported channels.
- The fix is live in Edge Canary and will ship in the next update (build 148+).
- The change reduces exposure for administrators who could dump passwords from other users’ Edge processes.
- Microsoft previously added a feature to protect against malicious extensions and restricted IE mode after zero‑day exploits.
- The update is part of the Secure Future Initiative and addresses a design that was “by design.”
- The change applies to all supported Edge releases, including enterprise Extended Stable channel.