3 Sources
[1]
Microsoft Recall can still nab credit cards, passwords, info
Our tests have shown there are ways to get around the promised security improvements exclusive Microsoft Recall, the AI app that takes screenshots of what you do on your PC so you can search for it later, has a filter that's supposed to prevent it from screenshotting sensitive info like credit
[2]
Microsoft's Windows Recall is reportedly still capturing passwords and Social Security numbers even after its relaunch
New report finds security loopholes still exist in this controversial Windows 11 feature The controversial Microsoft Windows Recall AI app may still be in need of security work according to testing from the UK technology site, The Register. The app, which takes screenshots of everything you do on
[3]
New report alleges Microsoft Recall is still screenshotting credit card numbers and passwords
Recall's security issues might not have been completely eliminated. Microsoft Recall's security woes have come back to the fore after a test caught the AI screenshotting tool capturing sensitive data (again). Ahead of its public beta release in April, Microsoft made a slew of security updates to
Share
Copy Link
Recent tests reveal that Microsoft's Recall AI app, designed to capture PC activity, still has security flaws allowing it to screenshot sensitive information like passwords and financial data.
Microsoft's AI-powered screenshot tool, Recall, is once again under scrutiny for its ability to capture sensitive information, despite recent security updates. Introduced in 2024 as an exclusive feature for Copilot+ PCs, Recall was designed to take screenshots of user activity for easy searching later. However, recent tests have revealed that the app's security measures are still falling short of expectations
1
.
Source: Tom's Guide
The Register's investigation found that Recall's "Filter sensitive information" setting, which is enabled by default, fails to consistently protect user data. While the filter successfully blocked some instances of financial information and passwords, it struggled with less obvious presentations of sensitive data
1
.For example:
The inconsistent filtering raises significant concerns about the potential misuse of captured data. If a malicious actor gains access to a system with Recall enabled, they could potentially retrieve a wealth of sensitive information
2
.
Source: The Register
Adding to these concerns, The Register's test revealed that Recall screenshots could be accessed remotely using just a PIN, bypassing the supposed requirement for biometric authentication through Windows Hello Enhanced Sign-On
3
.Related Stories
When contacted about these findings, Microsoft declined to comment. However, the company has previously acknowledged that the filter is not perfect and has encouraged users to report issues through the Feedback Hub
1
.Users do have some control over Recall's behavior:

Source: PC Gamer
Despite being labeled as a "preview" app, Recall is being actively promoted during the Windows setup process on new Copilot+ PCs. This aggressive push, combined with the persistent security issues, has led to continued criticism of the feature
3
.As AI-powered tools become more integrated into operating systems, the balance between functionality and privacy remains a critical concern. The ongoing issues with Recall serve as a reminder of the challenges in developing AI systems that can reliably protect sensitive user data while providing innovative features.
Summarized by
Navi
[1]
[2]
13 Dec 2024•Technology

15 Apr 2026•Technology

26 Apr 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
