Browser vulnerability: passwords stored in plain text

VG word pixels

Chrome, Edge and Firefox

A vulnerability in Google Chrome allows passwords to be read in plain text. Edge and Firefox are also said to be affected. However, Google does not want to patch it.

News

VG word pixels

Browser test 2020: The new Edge vs. Chrome & Firefox
All Chromium browsers appear to be affected by the vulnerability.
© Intarapong / shutterstock.com / Google / Mozilla / Microsoft

Several popular Chromium-based browsers are affected by a vulnerability that allows passwords to be read in plain text. The vulnerability was discovered by accident by security researcher Zeev Ben Porat Cyberark. According to him, these are “quite concerning” – “quite worrying”.

When using the browser, passwords and other data such as URLs, active cookies and user names are therefore stored unencrypted in the Chrome memory. However, attackers can also actively load all passwords stored in the browser’s password manager into memory.

The data stored in memory can then be extracted by attackers. By comparing the memory before and after the user logs into a service, the password used can be found out in a targeted manner. Since session cookies are also stored in the memory, two-factor authentication could even be bypassed.

A similar gap was already in 2015 by Satyam Singh of info sec discovered and disclosed.

Cyberark already suspected in the original article that other Chromium browsers such as Edge are also affected by the vulnerability. Of the IT blogger Günter Born was able to confirm this in several tests. But the problem also seems to exist with Mozilla’s Firefox.

Zeev Ben Porat reported the vulnerability to Google on July 29, 2021. However, the company informed him that it would not fix the vulnerability and referred to its own Security FAQ. The problem can only be exploited if the attackers have physical access to the device. This is outside of Chrome’s threat model. The browser must rely on the fact that the local user can be trusted.

According to Born, this statement is correct in theory, but falls short in this case: “Passwords should not be found in clear text in the browser memory.”

Microsoft Edge Logo 2019

update available

Edge Browser: Critical Vulnerability Warning

A vulnerability with risk level High was discovered in Edge. Microsoft fixes the vulnerability in the browser with an update.

14.6.2022 from
Alan Friedrichs

Continue to home page

more on the subject

Internet security - safe surfing (icon image)

Internet security

Google Chrome vs. Firefox, Opera & Edge: Browsers in…

Google Chrome is the undisputed top dog among browsers. But is the browser good at security and privacy? In our test he has to…

CPU, RAM, Malware & Co.: Fix PC problems - this is how it works

Update now

After BSI warning: Update for Google Chrome and Microsoft…

Chrome and Edge receive a security-critical update. The new versions close some vulnerabilities that the BSI classified as dangerous…

Windows 11 switch browsers

Switch to Chrome, Firefox and more

Windows 11 Tips: Change default browser

Windows 11 may make many things easier, but it complicates changing your preferred browser. We show how to change the default browser in Windows 11…

Browser test 2020: The new Edge vs. Chrome & Firefox

browser ranking

Microsoft Edge: 2nd place in the world for desktop browsers

Microsoft Edge has become more popular and is now the 2nd most used browser in the world. Safari and Firefox have to back down.

Microsoft Edge Logo 2019

update available

Edge Browser: Critical Vulnerability Warning

A vulnerability with risk level High was discovered in Edge. Microsoft fixes the vulnerability in the browser with an update.

Reference-www.pc-magazin.de