---
title: Plaintext in Memory: Revisiting Browser Password Security
description: This blog post shows how browsers expose passwords in memory and how they can potentially be extracted.
image: https://avantguard.io/hubfs/Blog/Passwortsicherheit%20im%20Browser/title-small.png
---

[![avantguard](https://avantguard.io/hs-fs/hubfs/LogoInverted.png?width=254&height=120&name=LogoInverted.png "avantguard")](https://avantguard.io?hsLang=en)

- [Services](https://avantguard.io/en/services)
- [About Us](https://avantguard.io/en/über-uns)
- [Experience](https://avantguard.io/en/erfahrung)
- [Career](https://avantguard.io/de/karriere)
- [Research](https://avantguard.io/en/blog)
- [Contact](https://avantguard.io/en/kontakt)

 En

- [English](https://avantguard.io/en/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser)
- [German](https://avantguard.io/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser)

[![avantguard](https://avantguard.io/hs-fs/hubfs/LogoInverted.png?width=144&height=65&name=LogoInverted.png "avantguard")](https://avantguard.io?hsLang=en)

<https://avantguard.io/en/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser#dark-header__mobile-nav__mmenu>

[![Dark-logo-small-1](https://www.fthemes.net/hubfs/Dark-logo-small-1.png "Dark-logo-small-1")](https://avantguard.io?hsLang=en)

- [Services](https://avantguard.io/en/services)
- [About Us](https://avantguard.io/en/über-uns)
- [Experience](https://avantguard.io/en/erfahrung)
- [Career](https://avantguard.io/de/karriere)
- [Research](https://avantguard.io/en/blog)
- [Contact](https://avantguard.io/en/kontakt)

 En

- [English](https://avantguard.io/en/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser)
- [German](https://avantguard.io/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser)

[![avantguard](https://avantguard.io/hs-fs/hubfs/LogoInverted.png?width=144&height=65&name=LogoInverted.png "avantguard")](https://avantguard.io?hsLang=en)

<https://avantguard.io/en/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser#dark-header__mobile-nav__mmenu>

- [Services](https://avantguard.io/en/services)
- [About Us](https://avantguard.io/en/über-uns)
- [Experience](https://avantguard.io/en/erfahrung)
- [Career](https://avantguard.io/de/karriere)
- [Research](https://avantguard.io/en/blog)
- [Contact](https://avantguard.io/en/kontakt)

Current language: English

- [English](https://avantguard.io/en/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser)
- [German](https://avantguard.io/blog/klartext-im-speicher-neubewertung-der-passwortsicherheit-im-browser)

Offensive

# Plaintext in Memory: Revisiting Browser Password Security

This blog post shows how browsers expose passwords in memory and how they can potentially be extracted.

[Christian Bieg](https://avantguard.io/en/blog/author/christian-bieg)

 May 22, 2026

---

## Initial situation

In early May, it became publicly known that Microsoft Edge keeps stored passwords unencrypted in memory when the process starts

 ([https://x.com/L1v1ng0ffTh3L4N/status/2051308329880719730](https://x.com/L1v1ng0ffTh3L4N/status/2051308329880719730)). This allowed extracting saved passwords directly from the memory of `msedge.exe`.

Microsoft responded (see [https://microsoftedge.github.io/edgevr/posts/Saved-passwords-in-Edge-memory-what-were-changing-and-why/](https://microsoftedge.github.io/edgevr/posts/Saved-passwords-in-Edge-memory-what-were-changing-and-why/)) and introduced a change in version 148.0.3967.70 that prevents passwords from being present in decrypted form in memory at startup.

Based on this, we further investigated the handling of passwords in memory in Microsoft Edge and Google Chrome.

## Observation

 Our analysis revealed that when opening `edge://settings/autofill`, multiple stored passwords are still decrypted and held in memory. On this page, passwords are not displayed in plaintext by default, so there is no functional need to decrypt them at that point. 

It also turned out that this issue not only affects Microsoft Edge, but also Google Chrome.

![Plaintext in Memory: Revisiting Browser Password Security](https://avantguard.io/hs-fs/hubfs/Blog/Passwortsicherheit%20im%20Browser/title-small.png?width=1250&height=512&name=title-small.png)

# Automation

A direct call to `msedge.exe edge://settings/autofill` is not possible. The browser apparently only accepts certain URL schemes at startup (e.g. `http://` and `https://`), but not `edge://`.

 To make the behavior reproducible and automatable, we proceeded as follows: 

- Terminate all `msedge.exe` processes
- Back up the files in the directory `[User Data]/Default/Sessions`
- Deploy a prepared session containing a tab with `edge://settings/autofill`
- Start `msedge.exe --restore-previous-session` to force loading the session
- Extract the passwords from the process memory
- Terminate all `msedge.exe` processes
- Restore the original session files

We implemented a proof of concept that automates these steps. The approach works with both Microsoft Edge and Google Chrome. The proof of concept can be found here: [ChristianBiegAG/SavedPasswordsDumper](https://github.com/ChristianBiegAG/SavedPasswordsDumper)

## **Assessment**

We reported this behavior to the Chromium team on 2026-05-20. However, the issue was closed with reference to the so-called “Infected Machine” threat model, in which attacks with already existing code execution in the user context are not taken into account.

Regardless of this, the question arises as to what expectations should be placed on an integrated password manager. In many security designs, the principle applies that sensitive data is only decrypted when it is actually needed.

In this specific case, this means:

1. Decryption as late as possible (on-demand)
2. Restriction to the specifically required entries
3. Minimization of the time spent in memory
4. Optional additional user confirmation (e.g. via OS authentication or biometrics)

Other password managers (such as [Keepass](https://avantguard.io/blog/keepass-angreifen-und-h%C3%A4rten?hsLang=en)) implement these principles.

[Offensive](https://avantguard.io/en/blog/tag/offensive) [Research](https://avantguard.io/en/blog/tag/research) [Cleartext Credentials](https://avantguard.io/en/blog/tag/cleartext-credentials)

## Similar posts

<https://avantguard.io/en/blog/powershell-enhanced-logging-capabilities-bypass?hsLang=en>

Bypass

##### [PowerShell Enhanced Logging Capabilities Bypass](https://avantguard.io/en/blog/powershell-enhanced-logging-capabilities-bypass?hsLang=en)

A blog post about a new enhanced logging capabilities bypass for PowerShell, which allows to bypass transcription logging.

 Jann Lemm  Sep 6, 2021

<https://avantguard.io/en/blog/threadless-ops?hsLang=en>

Offensive

##### [Threadless Ops - Enhanced Shellcoding for Threadless Injections](https://avantguard.io/en/blog/threadless-ops?hsLang=en)

Process Injection is essential in red teaming and serves various strategic objectives, enabling attackers to expand their capabilities.

 Sandro Ackermann  Apr 17, 2025

<https://avantguard.io/en/blog/threadless-ops-ii-enhanced-evasion?hsLang=en>

Offensive

##### [Threadless Ops II – Enhanced Evasion](https://avantguard.io/en/blog/threadless-ops-ii-enhanced-evasion?hsLang=en)

In Threadless Ops II, we combine threadless injection with evasion techniques to bypass EDR heuristics. Using Crystal Palace lets us modularly...

 Sandro Ackermann  Feb 27, 2026

##### Menu

- [Home](https://avantguard.io/en/homepage)
- [Services](https://avantguard.io/en/services)
- [About Us](https://avantguard.io/en/über-uns)
- [Experience](https://avantguard.io/en/erfahrung)
- [Research](https://avantguard.io/en/blog)
- [Contact](https://avantguard.io/en/kontakt)

##### Services

- [Basic Health Check](https://avantguard.io/en/basic_health_check)
- [Penetration Testing](https://avantguard.io/en/penetration-test)
- [Red Teaming](https://avantguard.io/en/red-teaming)
- [AD Security Improvement](https://avantguard.io/en/ad_improvement)
- [HIST](https://avantguard.io/en/hist)
- [Other](https://avantguard.io/en/services)

##### Research

- [Cleartext Credentials](https://avantguard.io/en/blog/plaintext-credentials)
- [Overload Mapping](https://avantguard.io/blog/overload-mapping-vs.-memory-scanner)
- [Ransomware](https://avantguard.io/en/blog/what-really-helps-against-ransomware)
- [Red Teaming](https://avantguard.io/en/blog/red-teaming)
- [KeePass](https://avantguard.io/en/blog/attacking-and-hardening-keepass)
- [PowerShell Logging](https://avantguard.io/en/blog/powershell-enhanced-logging-capabilities-bypass)
- [AD CS](https://avantguard.io/en/blog/active-directory-certificate-services)

© 2026 avantguard cyber security AG

##### avantguard cyber security AG

Neue Jonastrasse 52   
8640 Rapperswil-Jona  
Switzerland  
+41 55 253 30 30  
[info@avantguard.io](mailto:info@avantguard.io)

![flagge_schweiz](https://avantguard.io/hs-fs/hubfs/flagge_schweiz.png?width=40&height=40&name=flagge_schweiz.png)

[Privacy Statement](https://avantguard.io/en/datenschutzerkl%C3%A4rung?hsLang=en)

[Follow us on LinkedIn](https://ch.linkedin.com/company/avantguard-cyber-security-ag) [Follow us on Twitter](https://twitter.com/avantguard_io) 

![](https://f.hubspotusercontent00.net/hubfs/7712601/back-to-top.png)