Microsoft Edge stores your passwords plaintext
The Edge password manager appears secure: encrypted storage, protected by Windows Hello. However, plaintext is stored in memory.
Microsoft Edge has long marketed its password manager as a digital fortress ,encrypted vault, Windows Hello gatekeeper, the whole cyber-medieval fantasy. Unfortunately, it turns out the drawbridge is up, the guards are asleep, and the treasure chest is… wide open in RAM.
Yes, you read that right. According to a Norwegian security researcher, Edge is casually keeping your passwords in plaintext, like it is 1998 and we are all storing secrets in Notepad titled "totally_not_passwords.txt".
A "feature" you did not ask for
In a plot twist nobody ordered, Edge reportedly loads all your saved passwords into memory, unencrypted. Not just the one you are using. Not just temporarily. All of them. Hanging out. Vibing. Completely readable.
This means that any attacker with access to your system's memory can simply peek in and go, "Oh look, a buffet". No cracking required. No hacking montage. Just copy, paste, profit.
Other password managers go through the trouble of encrypting data, decrypting only what's needed, and then cleaning up after themselves like responsible adults. Edge, on the other hand, seems to prefer a more "open concept" approach.
Security, but optional
Sure, Edge now asks for authentication before loading your passwords. Very reassuring, until you realize that once they are loaded, they are basically doing a meet-and-greet in your RAM with anyone curious enough to look.
It is like locking your front door but leaving all your valuables on the front lawn with a sign that says "Please do not take these".
Not a bug, but a choice
Here is the real punchline: according to reports, Microsoft apparently considers this behavior intentional. That is right, not a bug, not an oversight, but a deliberate design decision. Why? Great question. One that remains as mysterious as Clippy's disappearance.
What you should do
If you are currently trusting Edge with your passwords, now might be a good time to not do that anymore.
-
Delete saved passwords from Edge
-
Switch to a dedicated password manager
Here you can find Password Managers you will actually want to use in 2026.
Meanwhile, the researcher plans to release a tool so you can check whether your passwords are being stored in plaintext, because apparently that is something we need tools for now.