Microsoft's Recall Feature Faces Criticism After TotalRecall Reloaded Tool Regains Access to Data

Hagenah said he shared his findings with Microsoft in March, along with the necessary technical details and code.

Advertisement
Written by Sucharita Ganguly, Edited by David Delima | Updated: 16 April 2026 15:59 IST
Highlights
  • Research highlights gaps in Recall’s data access controls
  • Researcher says Recall data can be accessed after login
  • Microsoft says Recall behaviour aligns with system design

Microsoft had reworked Recall after facing criticism earlier

Photo Credit: Microsoft

TotalRecall Reloaded, a tool developed by cybersecurity researcher Alexander Hagenah, has raised fresh concerns about Microsoft's Windows Recall feature and how it handles sensitive user data. The research points to potential issues in how information is accessed after authentication, even though Microsoft had redesigned Recall with stronger protections. The company reportedly views the behaviour as part of its existing system design, but the findings highlight ongoing concerns about whether features that record user activity can remain both useful and secure.

TotalRecall Reloaded Highlights Ongoing Windows Recall Security Concerns

The Recall tool is built to pull data from Recall, an AI feature that takes regular snapshots of what appears on your screen so you can search through your past activity. Hagenah said his updated version can quietly run in the background and access that data once a user logs in through Windows Hello.

Advertisement

Microsoft had reworked Recall after facing criticism earlier, adding stronger protections like encryption, secure enclaves and biometric authentication. The company had said these changes would stop malicious software from taking advantage of a user's login to access stored data.

However, Hagenah explains that the protection does not fully work as intended. He said the system's secure storage is strong, but the boundary that controls how data is accessed breaks down too early. According to him, the tool can effectively follow a user's authentication process and then retrieve stored information.

Advertisement

The data Recall stores go beyond simple screenshots. It can include on-screen text, messages, emails, documents, browsing activity, timestamps, and AI-generated context, building a detailed picture of how a user interacts with their device.

Hagenah said he shared his findings with Microsoft in March 2026, along with the necessary technical details and code. He claims the company reviewed the report but did not consider it a security issue, stating that the behaviour aligns with how the system is meant to work and does not break any security boundaries.

Advertisement

Microsoft also said that measures like time limits and protections against repeated access help reduce the risk. Hagenah, however, disagreed and argued that these safeguards can be bypassed.

The Verge reported that the issue may stem from the way Recall delivers decrypted data to other processes after authentication. While the storage system itself remains secure, the method used to present that data could expose it to misuse.

Advertisement

Despite the concerns, Hagenah acknowledged that several parts of Recall's redesigned security, including its encryption and authentication model, are robust, according to the aforementioned The Verge report. He suggested that further improvements are needed in how data is handled after it leaves the secure environment.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Pad 4 to Launch in India With a 13,380mAh Battery on This Date
  2. Best Mobiles Under Rs. 40,000 in India
  3. Lumio Introduces Vision 9 (2026) and Vision 7 (2026) TVs in India
  4. OnePlus Nord CE 6 Lite Appears on Geekbench With This MediaTek Chip
  5. Vivo X300 Ultra Price Leaked: Here's How Much It Might Cost in Europe
  6. YouTube Finally Lets You Turn Off Shorts From Your Feed With This Setting
  7. Oppo F33 Pro 5G vs OnePlus Nord 6 vs Nothing Phone 4a Pro: Which One Should You Pick?
  8. Oppo Find X10 Key Specifications Leak as Find X9 Ultra Launch Nears
  9. Motorola Hikes Prices of These Tablets in India
  1. OnePlus Nord CE 6 Lite Appears on Geekbench With Dimensity 7400 Chip, Android 16
  2. Meta’s Planned Facial Recognition Feature for Smart Glasses Faces Opposition From Privacy Orgs
  3. Vivo X300 Ultra Pricing Surfaces Online via Retail Listing in Europe
  4. YouTube's New Option Lets Users Effectively Turn Off Shorts From Their Feed
  5. South Korea Plans Blockchain-Based Payments for Government Spending
  6. Amazon Launches AI Store to Help Users Discover and Shop AI-Powered Devices
  7. Motorola Razr Fold, Lenovo Legion Y70 to Launch Alongside Y900 Tablet During Lenovo's May 19 Event
  8. Apple Tap-to-Pay Vulnerability Demonstrated on Video as YouTuber Steals $10,000 From a Locked iPhone
  9. Adobe’s New Firefly AI Assistant Can Perform Complex Design Tasks With Text Prompts
  10. Crimson Desert Has Sold Over 5 Million Copies, Pearl Abyss Confirms
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.