Researchers recently found that Microsoft Edge actually loads all saved passwords into system memory in plain text the moment the browser launches. That means even if you’re not logging into anything, your credentials are already sitting there in readable form inside RAM. And yes, that includes every password you’ve stored in the browser.
Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them. pic.twitter.com/ci0ZLEYFLB
— Tom Jøran Sønstebyseter Rønning (@L1v1ng0ffTh3L4N) May 4, 2026
Now, to be clear, those passwords are still encrypted while stored on disk, which is standard practice across browsers like Google Chrome. The difference here is what happens after launch. While Chrome typically decrypts passwords only when needed, Edge appears to preload and keep them accessible in memory throughout the session, which effectively expands the window of exposure.
Such behavior has sparked veterans to look into this, and they discovered that credential extraction is significantly easier under the right conditions. If an attacker gains access to your system – whether through malware or elevated privileges – they could potentially dump the browser’s memory and retrieve passwords that you haven’t even used during that session.
It might be even worse for shared environments, because credential harvesting can be achieved at a much larger scale – all without complex exploitation techniques once access is obtained.

You’d think that it might just be another “vibe-coded” logic from some engineers over there, and it can be fixed if they wanted to. Well, emphasizing the “if” – because they acknowledged the behavior yet stated it is “by design”, so they are not changing things anytime soon.
While that argument isn’t completely wrong, sometimes a big wall of defense can be destroyed by chaining several “small vulnerabilities”, so only time will tell if MS decides to go preventive instead of passive in their security approach for Edge.
Also, use things like dedicated password managers and even physical fobs for logins if you’re paranoid or handling sensitive materials.









