- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,312
The team recognized the problem only after the publication of the crushing report.

Microsoft changes the work of the password manager in Edge after a public report that the browser at launch downloaded stored passwords in the memory of the process in open form. The company does not consider the situation a serious threat to users, but decided to reduce the excessive risk and change the mechanism of storing sensitive data.
The problem was previously reported by specialist Tom Yoran Sönstseister Rönning. According to Microsoft, the described scenario requires the attacker to already gain control of the device and can run malware on it. This level of access goes beyond the threat model of the browser password manager, since after compromising the system, any application can no longer reliably protect the data on its own.
Despite this assessment, Microsoft has acknowledged that Edge’s behavior can be made safer. Gareth Evans from the browser team said that Edge will stop downloading stored passwords in memory at the start. The change has already appeared in Edge Canary and will be included in the next update of all supported channels, including Stable, Beta, Dev, Canary and Extended Stable for corporate clients. We are talking about the assembly of 148 and newer versions.
Users do not need to manually change settings or transfer passwords. The update will come through the usual Edge delivery channel. Microsoft is revisiting with the Secure Future Initiative, in which the company revises the processing of sensitive data and reduces the possible surface of the attack even where there is not formally a new vulnerability.
Microsoft will also review the work with messages from specialists. The company acknowledged that it initially relied on common Chromium criteria, but wants to take into account scenarios where additional safeguards could reduce the risk to customers. In the future, the Edge team promised to explain its decisions more accurately and apply the approach with multi-level protection before.

Microsoft changes the work of the password manager in Edge after a public report that the browser at launch downloaded stored passwords in the memory of the process in open form. The company does not consider the situation a serious threat to users, but decided to reduce the excessive risk and change the mechanism of storing sensitive data.
The problem was previously reported by specialist Tom Yoran Sönstseister Rönning. According to Microsoft, the described scenario requires the attacker to already gain control of the device and can run malware on it. This level of access goes beyond the threat model of the browser password manager, since after compromising the system, any application can no longer reliably protect the data on its own.
Despite this assessment, Microsoft has acknowledged that Edge’s behavior can be made safer. Gareth Evans from the browser team said that Edge will stop downloading stored passwords in memory at the start. The change has already appeared in Edge Canary and will be included in the next update of all supported channels, including Stable, Beta, Dev, Canary and Extended Stable for corporate clients. We are talking about the assembly of 148 and newer versions.
Users do not need to manually change settings or transfer passwords. The update will come through the usual Edge delivery channel. Microsoft is revisiting with the Secure Future Initiative, in which the company revises the processing of sensitive data and reduces the possible surface of the attack even where there is not formally a new vulnerability.
Microsoft will also review the work with messages from specialists. The company acknowledged that it initially relied on common Chromium criteria, but wants to take into account scenarios where additional safeguards could reduce the risk to customers. In the future, the Edge team promised to explain its decisions more accurately and apply the approach with multi-level protection before.