This seems like a significant oversight for a modern browser. Credential material should be aggressively zeroed out after use to minimize the attack surface.