Browser Security
How to Remove Saved Passwords From a Shared Computer
Saved passwords on shared computers can expose accounts long after you leave. This guide explains how to remove browser passwords, sign out sessions, change risky passwords, and prevent future leaks.
Remove credentials and sessions together
To remove saved passwords from a shared computer, open the browser's password settings, delete saved logins, sign out of your accounts, remove your browser profile if you added one, and change important passwords from a trusted device if you are unsure what was saved.
A shared computer can be a family laptop, hotel computer, school device, workplace machine, library computer, or borrowed device. The risk is highest when you saved passwords, stayed signed in, synced your browser profile, or used sensitive accounts.
Do not enter current passwords into random cleanup tools. Use the browser and provider settings directly.
Why saved passwords on shared devices are risky
Anyone who uses the computer later may see saved usernames, autofill suggestions, active sessions, browsing history, downloads, and sometimes account data. Even if passwords are hidden, an active session may remain logged in.
Public or shared computers may also have unknown extensions, monitoring software, or malware. If you used one for email or banking, change passwords later from your own trusted device.
CISA recommends using MFA and keeping accounts protected beyond passwords. MFA can reduce damage if a password is exposed.
- Saved browser passwords.
- Active login sessions.
- Synced browser profile.
- Autofill details.
- Downloaded files.
- Unknown extensions or monitoring.
Check which browser profile was used
Look at the active browser profile and sync status. If your profile is signed in, sign it out and remove it from the device. Then remove saved passwords from Chrome, Edge, Safari, Firefox, or the browser used.
Google and Microsoft provide official password management pages for Chrome and Edge. Use those settings directly instead of third-party cleanup prompts.
Sign out from your own device too
From a trusted device, open important account security pages and sign out other sessions. Do this for email, banking, cloud storage, social media, password manager, phone carrier, and work tools.
If an account offers a session list, remove the shared computer.
Change passwords that may have been saved
Change passwords for high-value accounts used on the shared computer. Use unique passwords stored in a password manager. NIST recommends password managers because they help avoid reuse.
If the same password was reused elsewhere, change those accounts too.
Enable MFA
Turn on MFA for important accounts. CISA recommends MFA because it gives protection even when a password is exposed.
If you receive unexpected approval prompts later, deny them and review account activity.
Remove downloads and autofill data
Delete sensitive downloads, clear autofill entries you added, and remove your browser profile. Do not rely only on clearing history; saved passwords and sessions are separate settings.
If the computer is public or belongs to an organization, do not attempt unauthorized system changes.
Avoid shared-device sign-ins later
For future use, avoid signing into email, banking, password managers, or cloud storage on shared computers. If you must, use private browsing, never save passwords, and sign out completely.
Change passwords from a trusted device if anything felt suspicious.
Frequently asked questions
Is clearing browser history enough?
No. Saved passwords, active sessions, autofill, downloads, and synced profiles may remain.
Should I change passwords after using a shared computer?
Yes for important accounts if you saved passwords, stayed signed in, or do not trust the device.
Can MFA help if a password was saved?
Yes. MFA adds another barrier, but you should still remove saved access and change risky passwords.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
