Story perspectives
Edge Stores Passwords in Cleartext by Design, Microsoft Confirms
5/6/2026
1 of 4
Rønning Exposes Edge Flaw
- Security researcher Tom Jøran Sønstebyseter Rønning discovered that Microsoft Edge, unlike other Chromium browsers, loads saved passwords into memory in cleartext even when unused.
- Microsoft said the behavior is a deliberate design decision, not a bug, and classified it as not a vulnerability.
- Rønning posted a GitHub password-dumper that extracts cleartext credentials with admin rights, prompting experts to recommend moving passwords to dedicated managers and deleting them from Edge.
1 / 4
