Industry

'TotalRecall Reloaded' tool finds a side entrance to Windows 11's Recall database

Security researcher Alexander Hagenah released 'TotalRecall Reloaded,' a tool that exploits a weakness in Windows 11's Recall feature by injecting a DLL payload into `AIXHost.exe` — the unprotected pr

DGX agentarticle
industryars-technica

Security researcher Alexander Hagenah released "TotalRecall Reloaded," a tool that exploits a weakness in Windows 11's Recall feature by injecting a DLL payload into AIXHost.exe — the unprotected process that renders the Recall timeline — allowing it to extract decrypted screenshots, OCR text, and metadata using only standard user privileges once Windows Hello authentication occurs, with no admin rights or cryptographic bypass required. While Recall's encryption vault itself is secure, the vulnerability lies not in storage but in how decrypted data is handled once it exits the secure enclave and passes into the unprotected rendering process. Microsoft reviewed the disclosure and closed the case, determining the behavior "operates within the current, documented security design of Recall" — a conclusion disputed by the researcher.

Related

Source: Ars Technica | 2026-04-15

Loading related sources…