Every time you sign up or log in somewhere new, the browser offers to save the password. Some people always press "Save". Others always decline, because they once heard that saving passwords in the browser is dangerous.
Both have a point, but for different reasons than people usually imagine.
Compared with what
Security is always relative. The more useful question is: if the password isn't stored in the browser, where is it stored?
For most people the answer is memory. Human memory can't hold thirty different random passwords, so what happens is one or two passwords get reused across every account, often with small variations. That's far more dangerous. Once one small site leaks, attackers try the same email and password on your email, marketplace, and social media accounts. The attack is automated and cheap.
A browser's built-in password manager solves that: each account can have a different long password, and you don't need to remember any of them. Guidance on strong passwords is in strong Wi-Fi passwords; the principles are the same for online accounts.
There's another benefit that rarely gets mentioned: autofill only appears on the correct site address. On a lookalike page with a similar address, the browser stays silent. That's a useful warning sign against phishing pages.
The real risks
The weakness isn't in password saving itself, but in three points around it:
- Data-stealing programs (infostealers). Malware already installed on a computer can copy saved passwords, session cookies, and autofill data, then send them to the attacker. This is the most common way browser passwords are stolen, and it usually arrives through pirated software, "cracks", or files sent over chat. An example is covered in APK file scams over WhatsApp.
- Unlocked devices. A laptop left open on a café table or a phone with no screen lock lets anyone holding it into accounts whose passwords are saved.
- The sync account. Chrome passwords sync to your Google account, Safari's to your Apple account. If that account falls, the whole vault opens with it.
Note that infostealers can also record keystrokes and steal sessions that are already signed in. Not saving passwords doesn't help much once the computer is infected. Protecting the device from infection matters far more than choosing where to keep passwords.
Staying safe
- Set a screen lock on your phone and laptop, and have it lock automatically after a few minutes.
- Protect your Google, Apple, or Microsoft account with a unique password and two-step verification. See two-step verification and account security.
- Don't install pirated software or files from unclear sources. They're the main source of infostealers.
- Check the password report. Chrome, Safari, and Firefox flag passwords that are weak, reused, or found in data breaches. Change the flagged ones, starting with email and banking.
- Don't save passwords on shared computers, such as internet cafés, libraries, or office machines used in turns.
- Use passkeys when offered. A passkey replaces the password with a key tied to your device that can't be typed into a fake site.
When a separate password manager fits better
| Situation | Sensible choice |
|---|---|
| One browser brand on every device | The built-in manager is enough |
| iPhone with a Windows laptop, or a mix of browsers | A separate manager available on every platform |
| Sharing Wi-Fi, streaming, or business passwords with family or staff | A manager with sharing and shared vaults |
| Passwords for a work account managed by your employer | Follow company policy; don't mix with personal accounts |
One thing worth avoiding is keeping a password list in phone notes, photos, or an unprotected spreadsheet. That gives you every weakness of digital storage with none of its protections.
If passwords have already been stolen
Signs include sign-in alerts from unfamiliar devices, a changed recovery email, or friends receiving odd messages from your account. Clean the suspected device first, then change passwords from a different, clean device. Changing passwords from a computer that's still infected just hands the new ones to the attacker. The full steps resemble what to do after Wi-Fi is hacked, and if personal data has spread, see how to report a personal data leak.
Frequently asked questions
Which is safer, a separate password manager or the browser's built-in one?
For most people the gap is small compared with the gap between using a password manager and not using one at all. A separate manager wins when you use several browsers or device brands, and usually offers tidier family sharing.
Can someone who borrows my laptop see my saved passwords?
Yes, if the laptop is open with no screen lock. Modern browsers ask for the device password or a fingerprint before revealing saved passwords, but autofill on sites still works. A screen lock is the first layer.
If my Google or Apple account is hacked, do all my passwords leak too?
Passwords synced to that account can be exposed. That's why the main account needs a strong, unique password and two-step verification, ideally with a passkey or authenticator app rather than SMS.