Researchers infer keystrokes, browsing and messaging actions through metadata without elevated privileges; limited mitigation leaves wider risks unresolved
Researchers from the Graz University of Technology have discovered that file-notification services in Linux, Windows, macOS, and Android can expose users’ activity to other applications on the same device.
The attacks do not require administrator privileges or access to file contents. Instead, they exploit notifications that reveal when files are created, changed, or removed. By analyzing file paths, names, and event timing, an attacker can infer keystrokes, browsing behavior, and private-message activity.
These notification mechanisms support common software such as text editors, antivirus tools, and synchronization clients:
- Linux uses inotify — monitoring the readable `/dev/input` directory allowed the researchers to identify the timing of individual keystrokes, even though the monitoring process could not open the files themselves. In tests involving seven users, the method recognized keystrokes with accuracy ranging from 93.1% to 100%. Another Linux technique tracked which system fonts Firefox loaded and used those patterns to identify websites from a list of 100 with 87.9% accuracy.
- Android provides FileObserver — An application that requested no permissions could observe WhatsApp media-related events on Google Pixel and Samsung Galaxy phones, indicating when photos, videos, or documents were sent or received.
- Windows relies on ReadDirectoryChangesW — A watcher placed on the root of the `C:\` drive received full paths for file changes across the computer, including activity inside other users’ home directories. Using this information, the researchers fingerprinted Firefox browsing sessions and identified sites from the top 1,000 with 97.8% accuracy.
- macOS uses FSEvents — Attackerscould monitor globally readable locations and system property list files, and observe system-wide events such as application installs and removals; app launches and some app interactions; audio input/output changes; power setting changes; Bluetooth and printer device changes; Network/DNS changes triggered by cable or interface events; volume mount/unmount events.
Although each system is intended to tell legitimate applications about relevant file changes, the researchers have found that the resulting metadata can disclose more information than expected.
More details in November 2026
Linux has received a limited mitigation through [CVE-2025-68788], which blocks certain access and modification events involving special files. However, the researchers have said the change addresses only the most serious Linux cases, and does not eliminate the wider problem.
Microsoft has described the Windows behavior as “by design,” arguing that notifications do not expose file contents.
Apple and Google have not publicly commented, and no Android or macOS fixes have been announced.
The work is scheduled for presentation at the ACM Conference on Computer and Communications Security (CCS 2026) in The Hague from 15–19 November 2026. The proof-of-concept code can be found in GitHub, with no real-world exploitation found.
Programmers are recommended to treat file notifications as a form of data access, and limit events to only the files that an application is authorized to inspect.
