Microsoft’s controversial Windows Recall feature is facing new scrutiny, with a cybersecurity researcher claiming the company’s redesigned safeguards can still be bypassed.

Recall, an AI-powered feature designed to capture and index snapshots of nearly everything a user does on their PC, was previously delayed for almost a year following backlash from security experts who labelled it a “privacy nightmare”.

Despite a major overhaul, fresh concerns are now emerging.

Swiss-based cybersecurity expert Alexander Hagenah (pictured) has released a new proof-of-concept tool, TotalRecall Reloaded, which he says can extract sensitive data stored by Recall. The tool builds on earlier work that exposed flaws in the feature’s original version.

Microsoft’s redesign introduced a secure “vault” for Recall data, protected by Windows Hello biometric authentication and a virtualised security enclave. The company said these measures would prevent malware from accessing data, even if it attempted to exploit user authentication.

However, Hagenah argues the protections fall short in real-world scenarios. His tool can run silently in the background, trigger a Windows Hello prompt, and once the user authenticates, extract the entire Recall history – including screenshots, messages, emails, documents and browsing activity.

“This is exactly the kind of ‘ride-along’ attack Microsoft said it had prevented,” Hagenah claims, adding that the system’s trust boundary “ends too early”.

Microsoft disputes the findings, stating the behaviour is consistent with how Windows is designed to operate and does not represent a security vulnerability. The company also points to safeguards such as authentication timeouts and anti-hammering protections to limit abuse.

But Hagenah maintains these protections can be bypassed and says the issue lies in how decrypted data is handled after authentication. While he praised parts of the redesign, including the underlying secure enclave, he believes Microsoft has not fully met its own security goals.

With Recall still limited to select Copilot+ PCs and opt-in users, questions remain about whether Microsoft can win back trust before a wider rollout.