Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI Has a New AI Model Built for Biology and Science

    Today’s NYT Wordle Hints, Answer and Help for April 18 #1764

    Today’s NYT Connections Hints, Answers for April 18 #1042

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • Shop
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    AI News TodayAI News Today
    Home»Chatbots»“TotalRecall Reloaded” tool finds a side entrance to Windows 11’s Recall database
    Chatbots

    “TotalRecall Reloaded” tool finds a side entrance to Windows 11’s Recall database

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    "TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The problem, as detailed by Hagenah on the TotalRecall GitHub page, isn’t with the security around the Recall database, which he calls “rock solid.” The problem is that, once the user has authenticated, the system passes Recall data to another system process called AIXHost.exe, and that process doesn’t benefit from the same security protections as the rest of Recall.

    “The vault is solid,” Hagenah writes. “The delivery truck is not.”

    The TotalRecall Reloaded tool uses an executable file to inject a DLL file into AIXHost.exe, something that can be done without administrator privileges. It then waits in the background for the user to open Recall and authenticate using Windows Hello. Once this is done, the tool can intercept screenshots, OCR’d text, and other metadata that Recall sends to the AIXHost.exe process, which can continue even after the user closes their Recall session.

    “The VBS enclave won’t decrypt anything without Windows Hello,” Hagenah writes. “The tool doesn’t bypass that. It makes the user do it, silently rides along when the user does it, or waits for the user to do it.”

    A handful of tasks, including grabbing the most recent Recall screenshot, capturing select metadata about the Recall database, and deleting the user’s entire Recall database, can be done with no Windows Hello authentication.

    Once authenticated, Hagenah says the TotalRecall Reloaded tool can access both new information recorded to the Recall database as well as data Recall has previously recorded.

    Bug or not, Recall is still risky

    For its part, Microsoft has said that Hagenah’s discovery isn’t actually a bug and that the company doesn’t plan to fix it. Hagenah originally reported his findings to Microsoft’s Security Response Center on March 6, and Microsoft officially classified it as “not a vulnerability” on April 3.

    11s database entrance finds recall Reloaded side tool TotalRecall Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleOpenAI updates its Agents SDK to help enterprises build safer, more capable agents
    Next Article NBA Playoffs 2026: How to Watch the Play-In Tournament Tonight
    • Website

    Related Posts

    Chatbots

    The RAM shortage could last years

    Chatbots

    VC Ron Conway says he has a ‘rare form of cancer’

    Chatbots

    AI chip startup Cerebras files for IPO

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    OpenAI Has a New AI Model Built for Biology and Science

    0 Views

    Today’s NYT Wordle Hints, Answer and Help for April 18 #1764

    0 Views

    Today’s NYT Connections Hints, Answers for April 18 #1042

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    OpenAI Has a New AI Model Built for Biology and Science

    0 Views

    Today’s NYT Wordle Hints, Answer and Help for April 18 #1764

    0 Views

    Today’s NYT Connections Hints, Answers for April 18 #1042

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.