logo

Microsoft Recall Flaw Exposes Decrypted User Data, Researchers Find

ID: e41583c5-ec59-5c1f-b153-fe775e06fe76

STIX ID: report--e41583c5-ec59-5c1f-b153-fe775e06fe76

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

TotalRecall Reloaded is a user-level DLL injection tool targeting Microsoft Recall: it injects a payload into AIXHost.exe (which lacks PPL/AppContainer protections) to access decrypted screenshots, OCR text, metadata, named entities, and AI-generated descriptions. The tool operates without admin rights, relies on timing or simulated UI to obtain Windows Hello–authenticated data, can persist access by patching DiscardDataAccess, and exploits inconsistent COM interface protections; Microsoft reviewed the report and closed the case as "Not a Vulnerability."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.