惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
D
Docker
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
博客园 - 聂微东
B
Blog RSS Feed
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
Vercel News
Vercel News
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
爱范儿
爱范儿
D
DataBreaches.Net
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
Recent Announcements
Recent Announcements
U
Unit 42
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
宝玉的分享
宝玉的分享
量子位
Stack Overflow Blog
Stack Overflow Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
Microsoft Confirms Surprising Edge Password Security U-Turn
Davey Winder · 2026-05-19 · via Forbes - Consumer Tech
Microsoft Edge logo on smartphone.

Microsoft pulls u-turn on Edge password security issue.

SOPA Images/LightRocket via Getty Images

Microsoft has now confirmed that a “defense-in-depth change will come to every supported version of Edge” after initially refusing to address a password vulnerability identified for users of the web browser password manager. When I first reported that a researcher had publicly disclosed the security vulnerability, whereby all saved passwords were loaded into memory, in plaintext, at startup, Microsoft said that this happened “by design” and the behavior fell “within the expected threat model.” That was 10 days ago. Now, Microsoft has said that it will “no longer load passwords into memory on startup,” and starting with version 148 and “every supported version of Edge” will get the update, the rollout of which is now being prioritized.

ForbesMy Password Has Been Stolen—What Happens Next?

The Microsoft Edge Saved Passwords Vulnerability Explained

A security researcher went public at the start of May after Microsoft told him that the password security vulnerability he had found in the Edge browser was by design, and therefore would not be moving forward with his vulnerability report or making any changes to rectify. “Microsoft Edge loads all your saved passwords into memory in cleartext,” Tom Jøran Sønstebyseter Rønning said, “even when you’re not using them.” I mean, if leaving decrypted plaintext passwords in Edge process memory after startup, regardless of whether they are used during that session, isn’t a security vulnerability, then, frankly, I’m not sure what is. Sure, an attacker would need to already have admin privileges to exploit it, but it remains a vulnerability regardless, in my never humble opinion. Regardless of whether it has an official Common Vulnerabilities and Exposures designation or not. Especially as none of the other Chromium-based web browsers tested displayed the same memory-saving issue according to Rønning.

ForbesMicrosoft Windows 11 Exploited 3 Times In 24 Hours By Zero-Day HackersBy Davey Winder

Why Microsoft Is Making An Edge Password Security U-Turn

Gareth Evans, the Microsoft Edge security lead, has now posted a detailed explanation of the changes that are being made to how passwords are saved in Edge memory, and why those changes are being made.

As part of Microsoft’s Secure Future Initiative, Evans said, the security team continuously reviews how Edge handles sensitive data in order to reduce the risk of any exposure. While maintaining that, as the risk begins after an attacker has access, the so-called vulnerability remains within the expected threat model, Evans admitted that there is still room to improve the browser security. “We will no longer load passwords into memory on startup,” Evans said, but in an effort to minimize data exposure through defense-in-depth improvements, the update provides “a practical step in that direction.”

Which sounds like a U-turn to me, and likely to you as well.

ForbesMicrosoft Windows 11 Exploited 3 Times In 24 Hours By Zero-Day HackersBy Davey Winder

The good news is that users of the Microsoft Edge password manager need to do nothing but wait for the version 148 update to reach them. Meanwhile, Evans confirmed that Microsoft is “reviewing how we handle researcher reports, with a focus on speed, clarity, and applying defense-in-depth thinking earlier.” I‘d like to think that is a success for both common security sense and media reporting pressure. And given the number of Microsoft security vulnerabilities that have been dropped recently, that has to be a good thing.