The middleman between apps and your hardware
Store apps run inside AppContainer sandboxes: they cannot touch location, camera, microphone or your documents directly — every request passes through a broker process that enforces the toggles in Settings → Privacy & security. RuntimeBroker.exe is that broker. When an app asks where you are, the broker checks the toggle, mediates the call and hands over the answer; when an app opens a file picker, the window you see belongs to the broker, not the app. The file lives in C:\Windows\System32, runs under your user account and starts on demand — which is why its copies appear and disappear in Task Manager.
- Location, camera and microphone access for packaged apps
- The file and folder picker dialogs in Store apps
- Notifications and live tile updates
- Access to media libraries: pictures, videos, music
- Permission checks against the app's declared capabilities
Why there are ten in Task Manager
Roughly one broker instance per app session. Windows starts a broker when a packaged app launches and retires it when the app fully exits — but Store apps suspend instead of exiting, so their brokers linger. Open the Start menu, launch Photos, Widgets, the Xbox app, a couple of PWAs installed from Edge — and you have your ten. In Process Explorer the parent of each instance tells you which app it serves. Normal footprint is a few MB to a few dozen MB each; when one instance crosses a few hundred MB and keeps growing, a specific app is misbehaving — historically the usual suspects were a broken Photos app or an app that had not been updated after a feature release.
When to worry and what not to do
The legitimate file lives in C:\Windows\System32 — verify via right-click → Open file location in Task Manager; a broker running from anywhere else deserves a Defender scan. The fixes, in order of politeness: close the Store apps you are not using, sign out and back in, restart. Resetting the misbehaving app (Settings → Apps → Advanced options → Reset) fixes a leaking broker where killing the process only resets the counter. What you must not do is delete the file, block it or apply registry hacks that disable it: without the broker, Store apps lose permission handling outright — they crash on launch or silently lose access to camera, location and files. It is infrastructure, not bloatware; the bloat is whichever app is feeding it.
Questions and Answers
Can I disable or delete RuntimeBroker.exe?
No. It is the permission broker for Store apps — removing or disabling it breaks app launches and access to camera, location and files. It lives in System32 and is protected for a reason.
Why is Runtime Broker using so much memory?
One of the apps it serves is leaking — typically after a feature update. Identify it with Process Explorer, then update or reset that app; killing the broker process itself only restarts the counter.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]