Security bug in Edge password manager

Honored Contributor

So in Edge password manager, you took care of this problem by showing a fixed number of stars to prevent unauthorized users from seeing the exact number of characters in each password.





but the problem is, you can still see the total number of password characters when you go to each website.







notice the upper password has 3 characters more and I checked and confirm that the number of stars correctly represent the number of characters in the unmasked password.


and since an attacker can see the websites names in plain text in Edge password manager:





all they have to do is to go to that website, click on the username/password field to view the exact number of password characters.


using Edge dev Version 87.0.664.8 (Official build) dev (64-bit)

(also sent using feedback button on Edge)


