incident-responsetrade-pressNewsThe Broadside1 min read

Microsoft plans Edge 148 fix for password memory flaw

Default software choices can carry credential architectures that no procurement memo or security review explicitly accepted.


TL;DR

Federal News Network reports Microsoft reversed its initial position that Microsoft Edge’s credential handling was by design after Norwegian researcher Tom Jøran Sønstebyseter Rønning showed the browser loaded the full saved-password vault into plaintext process memory for an entire session. Edge version 148 is set to stop loading passwords at startup. Agencies running shared Windows machines or persistent terminal sessions still have to unwind the harder problem: browser-stored passwords inside broad, legacy access environments.

Federal News Network’s account turns on a narrow technical fact with large agency consequences. Rønning’s proof of concept required elevated privileges to read Microsoft Edge process memory, so Microsoft’s initial view that administrator access was already outside the browser threat model had a legitimate piece. The missing piece was the yield: Edge reportedly made that access worth much more by keeping the saved-password vault in plaintext memory for the whole session.

FNN reports that Chrome and Brave, also Chromium-based, use app-bound encryption and decrypt credentials only at autofill. Edge’s reported model turned credential theft into a simpler timing problem, because the vault was available after launch rather than during a narrow user action. That matters in a market where, according to the article, infostealer malware is cheap, low-skill and built to scrape browser process memory. FNN says those tools stole 1.8 billion credentials globally in the first half of 2025.

Edge version 148 should stop passwords from loading at startup, which is useful engineering work. The agency problem is the installed-base decision that preceded the bug: Edge arrived as part of Windows across much of the public-sector estate, often without a deliberate credential-governance review. Shared workstations, disconnected terminal sessions and broad entitlements turn a browser vault into lateral movement fuel. The Monday work is dull and necessary: restrict browser password storage on shared systems, review terminal-session handling, tighten local administrator access, and rotate credentials where exposure is plausible.


Published ·Deep Fathom