This means an attacker with admin privs access can dump the process memory and find creds without issue.
Another L for built-in browser password managers.
This means an attacker with admin privs access can dump the process memory and find creds without issue.
Another L for built-in browser password managers.
I confirmed this myself. Even when the password manager is disabled, the cleartext remains in memory.

(That’s not my password)
Now to dump the password, you need admin privileges, so there’s a valid argument that this is of limited utility. But especially for heavy SSO environments, the ability to easily dump this process and grab all browser-stored passwords, even as a local admin, is a powerful pivot.
I would argue in an enterprise environment where there are potentially many admins to your work machine, this could allow for comprised (either technically or morally) admins to have access to unauthorized work or personal information. This seems like a terrible oversite considering Windows is forcing a TPM chip at install anyway.