Microsoft reverses course on Edge password handling but denies users were ever at risk

In this photo illustration a Microsoft Edge logo of a web browser developed by Microsoft is seen on a smartphone and a pc screen.
(Image credit: Getty Images | SOPA)

Microsoft Edge will no longer load all your passwords into memory in plaintext on startup. The upcoming change comes shortly after a security researcher discovered and disclosed the behavior.

When it comes to security, it's better to be safe than sorry. That's the core message Microsoft shared when explaining why its Edge browser will no longer load passwords into memory on startup.

"Based on our existing criteria, this behavior falls within the expected threat model, since the risk begins after an attacker has already compromised the device. At the same time, we believe there’s opportunity to improve. In this blog, we’ll show you what we’re changing and why."


Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.


Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.