Microsoft Edge keeps stored passwords in memory as readable text. According to researcher, it's not a bug
A substantial part of the dispute isn't about whether passwords can appear in memory, but whether Microsoft considers it a security vulnerability.

Security researcher Tom Jøran Sønstebyseter Rønning pointed out behavior of the password manager in Microsoft Edge that can be a problem especially in shared or corporate environments. According to his findings Edge, on startup, loads the stored passwords in the given profile into the process memory as readable text. This is said to happen even if the user never opens the service and doesn't use the password during the session.
Rønning published a proof-of-concept tool EdgeSavedPasswordsDumper to demonstrate that stored credentials can be obtained from Edge's memory in readable form. In the project's description on GitHub he states that the tool was created for educational and research purposes and that the issue is particularly serious on terminal servers or in similar shared environments.
Passwords are encrypted on disk, the problem is in memory
Microsoft states in its documentation that Edge stores passwords on disk encrypted using AES and the key is protected via the operating system's storage, for example DPAPI on Windows. But that doesn't address the situation where the browser is running and, according to the researcher, the passwords are present in the process memory as plaintext.
This is where the difference between protection "at rest" and protection "in use" arises. The stored password file may be encrypted, but if the application loads all passwords into RAM in readable form on startup, a different type of risk opens up. An attacker who can read the process memory doesn't need to bypass the encryption of the stored data.
Biggest risk: terminal servers, VDI and shared machines
It's not a scenario where anyone could get the passwords remotely just by visiting a website. Exploitation, according to available information, requires local access, malware running in the user's session or administrative privileges in an environment where multiple user sessions run.
That doesn't mean the risk isn't important. In corporate environments it can be critical, for example on terminal servers, Citrix, VDI or shared machines. If an attacker gains administrative access to such a system, they can, according to Rønning, read the memory of processes of other logged-in users and thereby obtain their stored credentials.
Microsoft: local malware is outside the browser's threat model
A substantial part of the dispute isn't about whether passwords can appear in memory, but whether Microsoft considers it a security vulnerability.
According to available reports and the researcher's statements, Microsoft did not classify the described behavior as a typical vulnerability but as an intentional design. In the password manager security documentation Microsoft also states that local malware and physical attacks are outside the browser's threat model. In other words: if the device is compromised and the attacker's code runs as the user, it can essentially do what the user can do.
This argument has technical logic, but it doesn't reassure all security experts. Critics argue that even with a compromised endpoint it makes sense to reduce the impact of an attack and not expose all stored passwords at once in readable form.
False sense of security around Windows Hello
From a typical user's perspective it can be confusing that Edge requires verification via Windows Hello, a PIN or the device password when manually viewing a saved password. That creates the impression that saved passwords are protected by additional authentication before access.
But if, according to the researcher, the passwords are already loaded in the process memory, the verification in the user interface only protects against someone easily viewing them by clicking in the browser settings. It doesn't necessarily protect against an attack that reads the running application's memory.
The risk for home users differs from that for companies
For an ordinary home user an important nuance applies: if an attacker has malware on the computer, the problem is already serious regardless of the specific password manager. Malware can capture the keyboard, clipboard contents, cookies, session tokens or data from running applications.
But the impact is different for companies. One compromised administrator account on a shared server can mean access to the memory of multiple users at once. And if employees have work credentials stored in Edge, a convenient feature can become a stash of credentials for the next phase of an attack.
What users and administrators should do
For regular users it makes sense to consider moving passwords from the browser to a standalone password manager and enable multi-factor authentication wherever possible. It's also advisable to review saved passwords in Edge and remove those that are no longer needed.
In companies the situation is clearer. Administrators should consider whether to allow saving passwords in Edge at all. Microsoft offers the PasswordManagerEnabled policy for this, which can be used in an organization to disable saving new passwords. It's important to add, however, that according to the documentation this may not automatically remove passwords already saved.
Practical measures:
- consider disabling saving passwords in Edge in corporate environments
- remove previously saved passwords from the browser
- use a standalone password manager with corporate management
- deploy MFA and ideally phishing-resistant methods where possible
- limit administrative rights on terminal servers and VDI
- monitor processes and tools that work with the browser's memory
- train users that the convenience of the built-in password manager is not the same as full protection of credentials
It's not just about Edge, but about the boundary of responsibility
The whole case is interesting mainly because it shows the difference between the manufacturer's formal threat model and the defenders' practical view. Microsoft can say that a compromised device is outside the browser's security model. Security teams, however, deal with the reality in which endpoints are compromised, malware exists, and minimizing the impact of an attack is part of defense.
That doesn't automatically mean Edge is "broken" for every user. For companies, administrators and anyone who stores important work credentials in the browser, however, it is a strong argument for reviewing settings and moving passwords to a tool that is primarily designed to manage them.