Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 2 sources · 14 days · First seen · Last updated
Microsoft Edge password security vulnerability
Overview
Security research in Denmark has identified a vulnerability in the Microsoft Edge browser regarding its handling of saved credentials. Testing revealed that passwords stored in the built-in manager can be recovered in clear text from a memory dump even after the browser has been closed and restarted.
While Microsoft has described this behavior as a “deliberate design choice rather than a bug,” experts noted that it deviates from standard security practices, which suggest passwords should only be decrypted at the moment of use and then cleared. This discovery has been highlighted alongside rising digital security threats in Denmark, including sophisticated phishing attacks targeting MitID, the country’s primary digital identity tool.
Entities
Microsoft Edge · MitID · Digitaliseringsstyrelsen · Microsoft · Computerworld
Timeline
-
7 days ago
[TECHNOLOGY] 2 sourcesDigital security threats rise for MitID users and Microsoft Edge browsersDanish users face rising MitID phishing attacks that grant scammers access to banking and tax data, alongside discoveries that Microsoft Edge may leave saved passwords readable in system memory.
-
20 days ago
[TECHNOLOGY] 2 sourcesMicrosoft Edge password manager reveals clear‑text passwords after restartA test in Denmark found Microsoft Edge’s password manager can expose saved passwords in clear text after a restart, a design choice that challenges typical security practices.
Sources
fashionsublime.com · pensionist.dk