< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 2 sources · 14 days · First seen · Last updated

Microsoft Edge password security vulnerability

Overview

Security research in Denmark has identified a vulnerability in the Microsoft Edge browser regarding its handling of saved credentials. Testing revealed that passwords stored in the built-in manager can be recovered in clear text from a memory dump even after the browser has been closed and restarted.

While Microsoft has described this behavior as a “deliberate design choice rather than a bug,” experts noted that it deviates from standard security practices, which suggest passwords should only be decrypted at the moment of use and then cleared. This discovery has been highlighted alongside rising digital security threats in Denmark, including sophisticated phishing attacks targeting MitID, the country’s primary digital identity tool.

Entities

Microsoft Edge · MitID · Digitaliseringsstyrelsen · Microsoft · Computerworld

Timeline

  1. 7 days ago

    [TECHNOLOGY] 2 sources
    Digital security threats rise for MitID users and Microsoft Edge browsers

    Danish users face rising MitID phishing attacks that grant scammers access to banking and tax data, alongside discoveries that Microsoft Edge may leave saved passwords readable in system memory.

  2. 20 days ago

    [TECHNOLOGY] 2 sources
    Microsoft Edge password manager reveals clear‑text passwords after restart

    A test in Denmark found Microsoft Edge’s password manager can expose saved passwords in clear text after a restart, a design choice that challenges typical security practices.

Sources

fashionsublime.com · pensionist.dk