"TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database
Alexander Hagenah says the tool can extract screenshots and OCR text without administrator privileges, while Microsoft says the issue is not a vulnerability.
- On April 3, 2026, Microsoft officially classified Alexander Hagenah's findings regarding Windows Recall as "not a vulnerability," rejecting claims of a security flaw in the feature.
- Security researcher Hagenah created the TotalRecall Reloaded tool to test Windows Recall, which captures screenshots and metadata of user activity to facilitate content searching.
- Hagenah reported that his tool injects a DLL into the AIXHost process, bypassing security boundaries after Windows Hello authentication to extract sensitive data.
- Microsoft maintains the architecture functions as intended, though Hagenah stated, "My research shows that the vault is real," disputing the company's security assessment.
- Despite not planning to address the issue, Microsoft notes that Windows Recall is optional and can be disabled to mitigate potential privacy risks.
19 Articles
19 Articles
Open-source tool decrypts all private data collected by Windows Recall on Copilot PCs
Alexander Hagenah previously exposed issues affecting Windows Recall with his TotalRecall tool, prompting Microsoft to redesign the feature around stronger architectural principles. Now, the security researcher is once again highlighting Recall's weaknesses with TotalRecall Reloaded. The updated tool can reportedly bypass protections in Recall and access private user data stored...Read Entire Article
Microsoft’s Windows Recall still allows silent data extraction
A cybersecurity researcher says Recall’s redesigned security model does not stop same-user malware from accessing plaintext screenshots and extracted text, without admin rights or exploits.
Microsoft Recall Under Fire Again As New Tool Exposes Potential Data Risks – channelnews
Microsoft’s controversial Windows Recall feature is facing new scrutiny, with a cybersecurity researcher claiming the company’s redesigned safeguards can still be bypassed. Recall, an AI-powered feature designed to capture and index snapshots of nearly everything a user does on their PC, was previously delayed for almost a year following backlash from security experts who labelled it a “privacy nightmare”. Despite a major overhaul, fresh concern…
Windows automatic screenshots feature called Recall can be leveraged by hackers to violate your privacy
Coverage Details
Bias Distribution
- 86% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








