Skip to main content

Windows, Linux, Android File Notification Systems Leak User Activity

0
Medium
Vulnerabilitywindowslinuxandroid
Published: 09/25/2026 (09/25/2026, 10:53:32 UTC)
Source: SecurityWeek

Description

Researchers demonstrated that file-change notification systems in Windows, Linux, Android, and macOS can be exploited to leak user activity such as keystroke timing, browsing habits, and media events without elevated privileges. The attacks rely on monitoring file system events accessible to unprivileged users or apps, revealing metadata like file names and event timing rather than file contents. On Windows, monitoring the system drive root can expose file paths in other users' profiles, enabling website fingerprinting. Linux kernel mitigations partially address the most severe issues, but no patches exist for Android or macOS. Microsoft considers the behavior by design and not a vulnerability. No in-the-wild exploitation is known, and proof-of-concept code is publicly available.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 11:02:53 UTC

Technical Analysis

File-change notification features in major operating systems allow applications to receive alerts when files are created, modified, or deleted. Researchers at Graz University of Technology showed that these features can be abused by unprivileged users or apps to monitor other users on the same system. The attacks do not expose file contents but use file names and event timing to infer sensitive user activities such as keystroke timing (revealing typing rhythms), visited websites via browser data folders, and media events in apps like WhatsApp. On Linux, watching readable folders can leak events from protected files. On Windows, monitoring the root of the system drive reveals full paths of changed files across user profiles. The Linux kernel has been partially hardened (CVE-2025-68788) to reduce severity, but no fixes exist for Android or macOS. Microsoft states this behavior is by design and recommends standard security best practices. Researchers have not observed active exploitation in the wild but have published proof-of-concept code.

Potential Impact

The vulnerability allows an attacker with local code execution under a separate user account to monitor file system events and infer user activities such as keystroke timing, browsing history, and media file events without accessing file contents. This can lead to privacy breaches and credential harvesting via UI spoofing (demonstrated on KDE Plasma 6). The impact is limited to information disclosure of metadata and timing, not direct file content access. No remote exploitation or privilege escalation is indicated. The attack requires local presence and code execution under a different user context.

Mitigation Recommendations

Linux kernel has a partial fix (CVE-2025-68788) that disables device file event generation, mitigating the most severe issues. Microsoft considers the Windows behavior by design and recommends limiting local access to trusted users and keeping systems updated. Administrators can enable protections documented by Microsoft for certain directory change notification scenarios. No patches or mitigations are currently available for Android or macOS. Users should follow vendor guidance and restrict untrusted local code execution. No urgent patching is mandated as the issue requires local attacker presence and does not expose file contents.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/","fetched":true,"fetchedAt":"2026-09-25T11:02:47.482Z","wordCount":1455}

Threat ID: 6ab654d7f7a7c54106ad2fab

Added to database: 09/25/2026, 11:02:47 UTC

Last enriched: 09/25/2026, 11:02:53 UTC

Last updated: 09/26/2026, 02:51:31 UTC

Views: 39

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses