# EdgeSavedPasswordsDumper: a C# proof of concept that Edge keeps saved credentials in process memory

> The tool demonstrates that Microsoft Edge holds autofill credentials in cleartext inside the parent Edge process, which matters on shared Windows machines. It is a research artifact, not a password recovery utility.

**L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper** — Proof of concept to show that Edge stores credentials in cleartext

- Repository: https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper
- Stars: 543 · Forks: 111
- Language: C#
- License: not declared
- Published: 2026-09-20 · Updated: 2026-09-20 · Language: en
- Canonical page: https://hysenlabs.com/projects/l1v1ng0ffth3l4n-edgesavedpasswordsdumper

## What EdgeSavedPasswordsDumper is actually for

The repository describes itself as a small educational tool that demonstrates Edge stores credentials in cleartext in process memory. That sentence is the whole product. It is not a browser extension, not a password manager, and not a recovery utility for a forgotten login. It exists to make a specific claim checkable: when a user saves a credential through the Microsoft Password Manager feature, for example through Autofill, the README states that all saved credentials sit in plaintext in the parent Edge process memory.

The intended audience is narrow. Someone studying memory inspection, someone preparing a responsible disclosure, or someone explaining to a security team why a terminal server is a different risk category from a single-user laptop. The author is explicit about their own background, writing that they are not an experienced C# developer and that the code may contain rough edges, inefficiencies, or non-idiomatic patterns. That is worth taking at face value when you read the source: the value here is the demonstration, not the engineering.

## Why the shared-machine case is the one that matters

On a personal laptop, a process that can read another process's memory is usually already running as you. The interesting case is a terminal server or any host where several accounts stay logged in at once. The README's argument is that an attacker on such a machine can reach all Edge processes for all logged on and disconnected users and dump their saved credentials. Disconnected sessions are the part people forget: the user is gone, the process is not.

Microsoft's position, as the README reports it, is that this is by design and will not be fixed. The repository also notes that Microsoft later backpedaled and fixed the feature in Edge version 148.0.3967.83, which narrows the window considerably. Both statements appear in the same requirements section, so the honest reading is that this is a historical demonstration with a documented end date rather than an ongoing finding. If you are citing it in a report, cite the version boundary too.

## How the dumper reaches another user's Edge memory

The mechanism is process memory inspection, and the repository layout is minimal: a README, a .gitattributes file, and a single project directory named EdgeSavedPasswordsDumper. There is no service, no driver, no injected DLL described in the README. The tool is a C# program that opens Edge processes and reads their memory looking for the cleartext credentials the browser has kept around.

The permission model follows directly from that. Run without Administrator rights and the program can only reach Edge processes started by the same user. Run elevated and the README states it can access and read memory from other users' Edge processes on the same machine. That elevation requirement is the difference between a curiosity and a demonstration of the terminal-server problem, and it is also the reason the project's own disclaimer leans so hard on legal and ethical responsibility.

One release is named No-Admin-Rights-Needed Update, so the non-elevated path was a deliberate addition rather than an afterthought. The later Binary-Sanitization release suggests the published binaries were cleaned up at some point, though the README does not describe what changed.

## Building and running it on Windows

The README lists .NET Framework 4.8.1 as the requirement, noting it was changed from 3.5 originally. That pins the tool to Windows and to a framework that ships with modern Windows installs, so there is no runtime to fetch in most cases. The README documents no install commands, no package to add and no command-line flags, so the build path is the ordinary one for a single C# project directory: open EdgeSavedPasswordsDumper/EdgeSavedPasswordsDumper in Visual Studio or build it with MSBuild, then run the produced executable. The repository name is the only identifier the README gives you for fetching the source, and the project directory inside the repository is where the .csproj lives.

Because no output format is documented either, run the built executable as your normal user first to see the same-user case, then, only on a machine you own or are authorized to test, run the same executable from an elevated prompt to see the cross-user behaviour the README describes. If the installed Edge is version 148.0.3967.83 or later, the README's own note about the fix means a clean result is the expected outcome, not a bug in your setup.

## The limitations the README hands you

The first limitation is the version ceiling. The README states the tool applies to Chromium-based Edge versions from 79 until 148 and that Microsoft fixed the feature in 148.0.3967.83. A proof of concept with a fixed upper bound is still useful for explaining what was wrong, but it will not reproduce on a patched browser, and anyone who runs it on a current build and sees nothing should not conclude the tool is broken.

The second is the permission boundary. Without elevation you see only your own Edge processes, which is exactly the case where the finding is least surprising. The cross-user result, which is the reason the project exists, requires Administrator rights and therefore a machine and a mandate that permit it.

The third is maturity. The author states plainly that they are not an experienced C# developer and that the code may contain rough edges. There is no documented test suite, no output schema, and no error handling described in the README. Treat the output as a lead to verify, not as a forensic record. It is also the wrong tool for recovering your own forgotten password on a modern Edge build, and the wrong tool for auditing password manager hygiene across an estate, since it reports on one browser's memory and nothing else.

## How it differs from Mimikatz and browser credential extractors

The obvious comparison is Mimikatz, which reads Windows credential material from LSASS and other protected stores. Mimikatz targets the operating system's authentication secrets and needs the privileges that go with that. This tool targets a user-space browser process and the credentials that browser has decrypted for autofill. Different store, different privilege story, different evidence.

The other comparison is the family of browser credential extractors that decrypt the on-disk Login Data database using the platform's key material. Those tools read what is at rest on disk; this one reads what is live in memory. That distinction matters for forensics, because a memory artifact disappears when the process exits and a disk artifact does not. It also matters for remediation: clearing saved passwords in the browser addresses the disk copy, while the README's claim is about the in-memory copy held by a running process.

## Maintenance, licence and upgrade cost

The repository is not archived, and the last push was on 2026-06-10, which is the same day as the v1.0.2 Binary-Sanitization release. Before that, v1.0.1 arrived on 2026-05-07 and v1.0.0 on 2026-05-06, so the whole public history is a few weeks of activity rather than a long-running project.

The licence is not stated in the README, and the repository entries listed do not include a licence file. That is a real gap if you intend to reuse the code rather than read it: without a licence grant, the default position is that no permission has been given, and the README's educational-use disclaimer is a statement of intent rather than terms you can rely on. Check the repository for a licence file before you copy anything into another codebase.

Upgrade cost is low in the ordinary sense, since the dependency is a framework that ships with Windows, but the ceiling imposed by Edge 148.0.3967.83 means the tool's useful life as a live demonstration is already bounded. Expect to maintain it as an explanation, not as a working exploit.

## Conclusion

Adopt this if you are doing memory forensics research, writing a disclosure, or need a concrete demonstration for a shared-terminal-server threat model where several users stay logged on. Do not adopt it as a password recovery tool for your own account, and do not treat it as a general credential auditor: the README says Microsoft fixed the behaviour in Edge 148.0.3967.83, so on current builds there may be nothing to show. Before relying on it, confirm which Edge build is installed on the target machine and whether you need an elevated process to reach other users' Edge instances, because the README states that without Administrator rights only Edge processes belonging to the same user are accessible.

## FAQ

### Where can I find Microsoft Edge saved passwords?

This project does not locate the on-disk password store. It reads credentials from the memory of the running parent Edge process, which the README says holds all saved credentials in plaintext.

### Is it safe to let Microsoft Edge save passwords?

The README argues it is problematic in a shared environment such as a terminal server, because an attacker can reach all Edge processes for all logged on and disconnected users. The author reports that Microsoft called this by design and later fixed it in Edge 148.0.3967.83.

### Does EdgeSavedPasswordsDumper need Administrator rights?

No. The README states it can run without Administrator rights, but then it can only access Edge processes run by the same user. With Administrator privileges it can read memory from other users' Edge processes on the same machine.

### Which Edge versions does EdgeSavedPasswordsDumper apply to?

The README says Chromium-based Edge versions from 79 until 148, and notes that Microsoft fixed the behaviour in 148.0.3967.83.

### What runtime does EdgeSavedPasswordsDumper require?

The README lists .NET Framework 4.8.1, changed from 3.5 originally, which keeps the tool on Windows.

## Sources

- [Issues](https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper/issues)
- [L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper on GitHub](https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper)
- [README](https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper/blob/main/README.md)
- [Releases](https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/l1v1ng0ffth3l4n-edgesavedpasswordsdumper
