Microsoft is testing new Windows 11 privacy controls that let users allow or block individual Win32 desktop applications from accessing the camera, microphone, location, and in some reports voice activation. The feature appeared in Windows 11 Insider Preview Build 26340.9212 for version 26H2 in the Experimental channel, where desktop apps can now trigger system permission prompts for camera and microphone access instead of relying on the long-standing shared device-wide toggles used for traditional Win32 software.
The controls were not documented in Microsoft's release notes and were first spotted by community testers, with reports indicating the rollout is limited to a subset of Insider systems and may be tied to the Win32SignatureIdentity feature flag. If broadly released, the change would close a notable privacy gap between classic desktop programs and Microsoft Store apps, while the same test build also completes removal of the legacy WMIC command-line tool, a utility frequently abused by ransomware operators during post-compromise activity.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
X user Jakub (@jakub25050) discovered and shared screenshots showing that build 26340.9212 lets users revoke camera and microphone access for specific Win32 desktop apps. His report helped reveal the feature because Microsoft had not documented it in release notes.
Microsoft released Windows 11 Experimental/Insider build 26340.9212 to the Experimental channel, where the new Win32 per-app privacy controls surfaced. The same build also finalized removal of the legacy WMIC command-line tool.
WindowsLatest verified on an Experimental Insider PC that Windows 11 build 26340.9212 exposes separate privacy entries for desktop apps and prompts for microphone and camera access. The outlet reported the feature covers camera, microphone, and location permissions and appears to be rolling out inconsistently.
According to Windows researcher Rafael Rivera, desktop apps had been listed collectively under the shared privacy switch since Windows 10 version 1903, without individual per-app controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcewindowslatest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.