NEWS “We hide the keys under the mat.” Microsoft voluntarily fed passwords to users viruses

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,580
How the company has been helping fraudsters clean other people’s accounts for years (and how it’s useful).
1778083403140.png
Microsoft Edge keeps passwords in the memory open until the browser closes. Security researcher Tom Ghoran Sönstoneer Ryongning drew attention to the feature that distinguishes Edge from other verified Chromium browsers: when running, the program immediately decrypts all the accounts, even if a person does not go to sites where these logins are needed.

Rönning claims that the decrypted records remain during the Edge process until the end of the session. For an ordinary user, this does not mean that any site or casual application will immediately see the logins. But if the attacker already knows how to read the memory of processes, theft is simplified: it does not need to wait for autocompleteding the form or opening the desired page, it is enough to remove data from the running Edge.

For comparison, the researcher brought Chrome. The Google browser reveals the password only at the time of use: when autofilling the form or when manually viewing the entry by the owner of the profile. Additionally, Chrome applies Application-Bound Encryption, a mechanism that links the keys to the proven Chrome process with system rights. Therefore, the secret appears in the open form for a short time and does not lie in the memory of the whole session.

The most important risk is related to terminal servers and shared working environments. With administrative rights, an attacker can read the memory of the processes of all incoming users. In the demonstration, Reunning showed that with such access you can get other people's passwords while Edge is open in user sessions.

Rönning reported on the discovery of Microsoft, but the company replied that Edge works according to the developers’ plan. Before publication, the researcher warned Microsoft that users and organizations could take into account the risk in password retention policies and browser settings.

Microsoft does not consider the situation to be a separate vulnerability. The company explained: access to browser data requires a already hacked device. According to Microsoft, developers choose a compromise between logging, convenience and protection speed, and working with memory data helps to log in faster on sites. Users are advised to install security updates and use antivirus.

Some experts also do not agree with the sharp assessment. They say that if the attacker has already received administrator rights and reads the memory of arbitrary processes, the system can actually be considered captured. With this level of access, the attacker is able to pull secrets from different browsers, run programs on behalf of the user and get to the data in other ways.

Different browser behavior is also important for corporate protection. The longer the secret lies in memory without encryption, the wider the window for informers, post-exploitation tools, and internal violators with increased rights. For companies with terminal servers, VDI and common workstations, the find gives an additional reason to prohibit the storage of passwords in the browser.

Security specialists have long advised not to use the built-in browser manager as the only protection of accounts. Infostilers hunt for logins, sessions files, tokens and cookies, and after infection, the computer pulls data in seconds. A more reliable approach includes a separate password manager, multifactor authentication and transition to passkeys where the service already supports the input without a regular password.

The output is simple: use Edge - hay, but after breaking the device, the margin of its strength is lower. If the working passwords are in Edge, it is worth revising the browser policies, prohibit the storage of accounting data, enable multi-factor protection and check services where the password can be replaced by passkeys.
 

CJNGCARTEL

Well-known member
Member
Joined
Jul 26, 2026
Messages
226
Reaction score
23
How the company has been helping fraudsters clean other people’s accounts for years (and how it’s useful).
View attachment 155
Microsoft Edge keeps passwords in the memory open until the browser closes. Security researcher Tom Ghoran Sönstoneer Ryongning drew attention to the feature that distinguishes Edge from other verified Chromium browsers: when running, the program immediately decrypts all the accounts, even if a person does not go to sites where these logins are needed.

Rönning claims that the decrypted records remain during the Edge process until the end of the session. For an ordinary user, this does not mean that any site or casual application will immediately see the logins. But if the attacker already knows how to read the memory of processes, theft is simplified: it does not need to wait for autocompleteding the form or opening the desired page, it is enough to remove data from the running Edge.

For comparison, the researcher brought Chrome. The Google browser reveals the password only at the time of use: when autofilling the form or when manually viewing the entry by the owner of the profile. Additionally, Chrome applies Application-Bound Encryption, a mechanism that links the keys to the proven Chrome process with system rights. Therefore, the secret appears in the open form for a short time and does not lie in the memory of the whole session.

The most important risk is related to terminal servers and shared working environments. With administrative rights, an attacker can read the memory of the processes of all incoming users. In the demonstration, Reunning showed that with such access you can get other people's passwords while Edge is open in user sessions.

Rönning reported on the discovery of Microsoft, but the company replied that Edge works according to the developers’ plan. Before publication, the researcher warned Microsoft that users and organizations could take into account the risk in password retention policies and browser settings.

Microsoft does not consider the situation to be a separate vulnerability. The company explained: access to browser data requires a already hacked device. According to Microsoft, developers choose a compromise between logging, convenience and protection speed, and working with memory data helps to log in faster on sites. Users are advised to install security updates and use antivirus.

Some experts also do not agree with the sharp assessment. They say that if the attacker has already received administrator rights and reads the memory of arbitrary processes, the system can actually be considered captured. With this level of access, the attacker is able to pull secrets from different browsers, run programs on behalf of the user and get to the data in other ways.

Different browser behavior is also important for corporate protection. The longer the secret lies in memory without encryption, the wider the window for informers, post-exploitation tools, and internal violators with increased rights. For companies with terminal servers, VDI and common workstations, the find gives an additional reason to prohibit the storage of passwords in the browser.

Security specialists have long advised not to use the built-in browser manager as the only protection of accounts. Infostilers hunt for logins, sessions files, tokens and cookies, and after infection, the computer pulls data in seconds. A more reliable approach includes a separate password manager, multifactor authentication and transition to passkeys where the service already supports the input without a regular password.

The output is simple: use Edge - hay, but after breaking the device, the margin of its strength is lower. If the working passwords are in Edge, it is worth revising the browser policies, prohibit the storage of accounting data, enable multi-factor protection and check services where the password can be replaced by passkeys.
Hello Hello to the cartels Hello, joining cartels Hello to those who want to join the cartels. Hello, those who want to join cartels, get involved in crime. Hello, those who want to join cartels, get involved in crime. Hello, those who want to join cartels, those who want to participate in crime, CJNG. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members, join now. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you'd like to join... Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you want to join, contact us. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you want to join, contact us on Telegram. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you are interested in joining, please contact us on Telegram. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you want to join, contact us on Telegram. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you are interested in joining, contact us on Telegram. There is a membership fee. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you are interested in joining, contact us on Telegram. The membership fee is 70. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you'd like to join, contact us on Telegram. The membership fee is $70. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you'd like to join, contact us on Telegram. The membership fee is $70.

@Cipher5Network

 
6,254Threads
84,139Messages
6,019Members
RainbowLatest member
Top Bottom