Researchers released TotalRecall Reloaded, a proof-of-concept attack that targets Microsoft Windows Recall by injecting into AIXHost.exe, the process that handles Recall content after Windows Hello authentication. The report says Recall’s advertised protections—VBS enclaves, AES-256-GCM encryption, TPM-backed keys, and secure handling in aihost.exe—remain in place, but decrypted screenshots, OCR text, metadata, named entities, and activity descriptions become accessible once they are passed to the less-protected rendering process. According to the researchers, malware running in the same user context can use DLL injection and internal COM interfaces to extract a detailed history of user activity, including messages, emails, documents, browsing context, timestamps, and AI-generated summaries, without administrator privileges or kernel exploits.
The findings add to long-running privacy and security concerns around Recall, which Microsoft had previously delayed after criticism that the feature continuously captures on-screen activity and stores searchable local history. Earlier reporting highlighted fears that Recall could collect sensitive content such as passwords and maintain it in locally accessible databases, even as Microsoft defended the design as on-device and privacy-conscious. In the new case, researchers also reported pre-authentication exposure of recent thumbnails, deletion of Recall history without Windows Hello checks, and alternate COM paths that allegedly bypass intended restrictions; they said the issues were disclosed to Microsoft in March 2026, but Microsoft closed the case as "Not a Vulnerability", stating the demonstrated behavior matched Recall’s documented security model rather than crossing a security boundary.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Public reporting detailed that Recall's encryption, TPM-backed keys, Windows Hello, and VBS enclave protections were implemented correctly, but decrypted data became exposed inside AIXHost.exe, which lacked stronger process protections. The report said same-user malware could access Recall data after legitimate authentication and potentially maintain access for the session.
A GitHub repository for TotalRecall Reloaded was published, describing a proof-of-concept that injects into AIXHost.exe to extract decrypted Recall screenshots, OCR text, metadata, and related data without administrator privileges. The publication also documented alleged pre-authentication issues and COM authorization bypasses.
Microsoft Security Response Center closed case 109586 and told the researcher the demonstrated behavior matched Recall's documented security design rather than a security boundary bypass. This left the reported AIXHost.exe exposure and related access paths unaddressed as a vulnerability.
The TotalRecall Reloaded researcher submitted a report, source code, and reproduction steps to the Microsoft Security Response Center describing post-authentication and pre-authentication weaknesses in Recall's architecture. The disclosure occurred in early March 2026.
Microsoft postponed the public preview rollout of Windows Recall, which had been planned for June 18, 2024, citing the need for additional security work and testing. The company said Recall would move first to the Windows Insider Program as privacy and security concerns mounted.
At a Stanford HAI event, Microsoft chief research scientist Jaime Teevan said Windows Recall stores data locally and does not send it to the cloud. The remarks came amid criticism that Recall could capture sensitive information and expose OCR text stored locally.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcegithub.com
Open sourcelinkedin.com
Open sourcewindowslatest.com
Open sourcewindowslatest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.