5 Sources
[1]
"TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database
Two years ago, Microsoft launched its first wave of "Copilot+" Windows PCs with a handful of exclusive features that could take advantage of the neural processing unit (NPU) hardware being built into newer laptop processors. These NPUs could enable some AI and machine learning features that could
[2]
Windows 11's Recall tool has been cracked open again, and Microsoft doesn't see that as a problem
* Recall's vault is solid, but its delivery path exposes decrypted screenshots, OCR text, and metadata in AIXHost.exe. * TotalRecall Reloaded injects into AIXHost.exe via COM calls to grab decrypted data -- no admin, no kernel exploit needed. * The researcher alerted Microsoft first, but the
[3]
One year after its rocky launch, Microsoft's Windows Recall still raises security red flags
Microsoft says its Recall app -- which captures and stores screen shots every few seconds -- is safe. Security researchers keep saying otherwise. Recall was originally billed as a "photographic memory" to store everything Windows users do on their computers. People could then see some of those
[4]
Cybersecurity experts raise the alarm over Windows Recall again: 'The vault door is titanium. The wall next to it is drywall'
Hacking tool supposedly creates "precisely the scenario Microsoft's architecture is supposed to restrict." Remember Windows Recall? The AI feature that essentially screenshots nearly everything you do on your PC in order to present users with a timeline of activity they can rewind back through? It
[5]
Researcher Questions Windows Recall Security Again Due to This Reason
* Research highlights gaps in Recall's data access controls * Researcher says Recall data can be accessed after login * Microsoft says Recall behaviour aligns with system design TotalRecall Reloaded, a tool developed by cybersecurity researcher Alexander Hagenah, has raised fresh concerns about
Share
Copy Link
A cybersecurity researcher has developed TotalRecall Reloaded, a tool that can extract decrypted data from Windows Recall by exploiting the AIXHost.exe process. Despite responsible disclosure, Microsoft claims the access patterns are consistent with intended protections and do not constitute a security vulnerability, sparking debate about whether features that record user activity can ever be adequately secured.
Windows Recall is under fire again. Security researcher Alexander Hagenah has released TotalRecall Reloaded, a tool that exposes what he believes are critical security and privacy risks in Microsoft's AI-powered feature designed for Copilot+ Windows PCs
1
. The feature, which captures screenshots every few seconds to create a searchable timeline of user activity recording, was delayed nearly a year after its original 2024 launch due to severe security flaws3
.
Source: GeekWire
Microsoft redesigned Recall with encryption, VBS Enclaves, and Windows Hello authentication to address initial concerns. But Hagenah's research suggests the security boundary ends too early in the data delivery chain
4
. While the vault storing Recall data remains "rock solid," the AIXHost.exe process that renders the timeline lacks the same protections1
.
Source: Ars Technica
The TotalRecall Reloaded tool operates by injecting code into AIXHost.exe without requiring admin privileges or kernel exploit techniques
2
. It waits silently in the background until a user authenticates with Windows Hello to access their Recall timeline. Once user authentication occurs, the tool can intercept and extract decrypted screenshots, OCR text, and metadata flowing through the AIXHost.exe process1
.Hagenah describes the vulnerability with a vivid analogy: "The vault door is titanium. The wall next to it is drywall"
4
. The fundamental problem isn't the encryption or the secure enclave—it's that decrypted content gets sent to an unprotected process for rendering. This creates precisely the scenario Microsoft's architecture was supposed to restrict: malware riding along with legitimate user access to steal data4
.The tool can access both new information being recorded and previously stored data once authentication happens. Some tasks, including grabbing the most recent screenshot and deleting the entire Recall database, can even be performed without Windows Hello authentication
1
.Hagenah responsibly disclosed his findings to Microsoft's Security Response Center on March 6, 2026. On April 3, Microsoft officially classified the issue as "not a vulnerability"
1
. David Weston, corporate vice president of Microsoft Security, stated that "the access patterns demonstrated are consistent with intended protections and existing controls, and do not represent a bypass of a security boundary or unauthorized access to data"4
.
Source: PC Gamer
Microsoft points to timeout periods and anti-hammering protection as safeguards that limit the impact of malicious queries
2
. However, Hagenah argues these protections can be bypassed, and the company's stance raises questions about data access controls for features that capture extensive user activity5
.The University of Pennsylvania's Office of Information Security released a warning on April 14, 2025, stating that Recall "introduces substantial and unacceptable security, legality, and privacy challenges," urging administrators to disable the feature
3
.Related Stories
The security vulnerability debate highlights a fundamental tension: making data ultra-convenient for users to access while simultaneously securing it against hackers proves extremely difficult
3
. Recall stores screenshots, emails, messages, web activity, browsing history, timestamps, and AI-generated context—building a detailed picture of how users interact with their devices5
.Anyone with access to a PC and the Windows Hello fallback PIN can potentially view this database. Even though Recall's content filters exclude sensitive financial information, the sheer amount of personal data it records creates significant privacy threat potential
1
. Malicious hackers have already written code to exploit Recall's memory and send screenshots to remote servers3
.Currently, fewer than 10% of Windows 11 PCs can run Recall, with the feature available only as an opt-in for Copilot+ PC users since April 2025
3
. Windows Insider program participants have had access for over a year. Microsoft's plans for wider availability remain unclear, with journalist Zac Bowden reporting in January 2026 that the company is "pulling back its Windows 11 AI push with a major Copilot and Recall rethink"3
.Some app developers are taking matters into their own hands. Signal Messenger forces Recall to ignore it by default, using a flag normally intended for different purposes
1
. The cybersecurity community continues watching whether Microsoft will address these concerns or if the feature's fundamental design makes adequate security impossible. For now, the gap between the secure vault and the vulnerable delivery mechanism remains a point of contention in the ongoing debate about AI features that monitor everything users do.Summarized by
Navi
[2]
[3]
02 Aug 2025•Technology

26 Apr 2025•Technology

13 Dec 2024•Technology

1
Technology

2
Technology

3
Science and Research
