Microsoft Recall Flaw Exposes Decrypted User Data, Researchers Find
ID: e41583c5-ec59-5c1f-b153-fe775e06fe76
STIX ID: report--e41583c5-ec59-5c1f-b153-fe775e06fe76
Feed Name: The Cyber Express
TotalRecall Reloaded is a user-level DLL injection tool targeting Microsoft Recall: it injects a payload into AIXHost.exe (which lacks PPL/AppContainer protections) to access decrypted screenshots, OCR text, metadata, named entities, and AI-generated descriptions. The tool operates without admin rights, relies on timing or simulated UI to obtain Windows Hello–authenticated data, can persist access by patching DiscardDataAccess, and exploits inconsistent COM interface protections; Microsoft reviewed the report and closed the case as "Not a Vulnerability."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
