Microsoft Recall Flaw Allows Data Extraction via DLL Injection

Microsoft Recall Flaw Allows Data Extraction via DLL Injection

First seen 10 Apr 2026, 08:15 UTC Itnews.AuThecyberexpressThevergeTweaktownCsoonline+3 83% similarity 51.9

Article Content

Browse articles
ThreatCluster

Researchers have identified a vulnerability in Microsoft's redesigned Recall feature for Windows 11, which allows attackers to extract decrypted user data, including screenshots and metadata. The flaw is attributed to the AIXHost.exe process, which lacks sufficient protections, enabling DLL injection attacks without requiring administrative privileges. The TotalRecall Reloaded tool exploits this vulnerability by embedding itself into AIXHost.exe after user authentication through Windows Hello. Microsoft has defended the architecture, stating that the behavior operates within the documented security design and does not constitute a vulnerability. The incident follows a previous discovery by researcher Alexander Hagenah in 2024, which led to Recall's temporary suspension. Microsoft redesigned Recall with enhanced security features, but the current issue highlights a gap in the implementation. No specific CVEs have been assigned to this vulnerability yet. The attack can occur with standard user permissions, raising concerns about user data security.

Key Points: • TotalRecall Reloaded exploits a flaw in AIXHost.exe, allowing data extraction post-authentication. • Microsoft claims the behavior is within the documented security design and not a vulnerability. • The attack requires no special privileges beyond those of the logged-in user.

ThreatCluster AI How this analysis works

Timeline

2024-06-01
Recall feature put on hold due to security weaknesses.
2025-04-01
Microsoft relaunches Recall with enhanced security features.
2026-03-06
Hagenah submits full disclosure to Microsoft's Security Response Centre.
2026-04-03
Microsoft closes case, stating behavior is within documented design.
2026-04-10
TotalRecall Reloaded tool publicly disclosed, demonstrating the exploit.

Community

Browse all →

Tracked Entities in This Story