Damn, I really thought the Recall database security would at least be, you know, secure. Turns out Microsoft did pretty much what I blogged about for WindowsApps, except you need to find a specific WIN://SYSAPPID instead. So to bypass the security just get the token for the AIXHost.exe process, then impersonate that and you can access the database, no admin required. Or, as the files are owned by the user, just grant yourself access using icacls etc :D

@GossiTheDog

You must see that ^

(Awesome) Blogpost btw form Tiraniddo:

https://www.tiraniddo.dev/2024/06/working-your-way-around-acl.html

Working your way Around an ACL

There's been plenty of recent discussion about Windows 11's Recall feature and how much of it is a garbage fire. Especially a discussion aro...

@tiraniddo roflflflflflflflfl recall is just letting hackers steall all your data without too much hassle.