Windows, Linux, Android File Notification Systems Leak User Activity
Researchers demonstrated that file-change notification systems in Windows, Linux, Android, and macOS can be exploited to leak user activity such as keystroke timing, browsing habits, and media events without elevated privileges. The attacks rely on monitoring file system events accessible to unprivileged users or apps, revealing metadata like file names and event timing rather than file contents. On Windows, monitoring the system drive root can expose file paths in other users' profiles, enabling website fingerprinting. Linux kernel mitigations partially address the most severe issues, but no patches exist for Android or macOS. Microsoft considers the behavior by design and not a vulnerability. No in-the-wild exploitation is known, and proof-of-concept code is publicly available.
AI Analysis
Technical Summary
File-change notification features in major operating systems allow applications to receive alerts when files are created, modified, or deleted. Researchers at Graz University of Technology showed that these features can be abused by unprivileged users or apps to monitor other users on the same system. The attacks do not expose file contents but use file names and event timing to infer sensitive user activities such as keystroke timing (revealing typing rhythms), visited websites via browser data folders, and media events in apps like WhatsApp. On Linux, watching readable folders can leak events from protected files. On Windows, monitoring the root of the system drive reveals full paths of changed files across user profiles. The Linux kernel has been partially hardened (CVE-2025-68788) to reduce severity, but no fixes exist for Android or macOS. Microsoft states this behavior is by design and recommends standard security best practices. Researchers have not observed active exploitation in the wild but have published proof-of-concept code.
Potential Impact
The vulnerability allows an attacker with local code execution under a separate user account to monitor file system events and infer user activities such as keystroke timing, browsing history, and media file events without accessing file contents. This can lead to privacy breaches and credential harvesting via UI spoofing (demonstrated on KDE Plasma 6). The impact is limited to information disclosure of metadata and timing, not direct file content access. No remote exploitation or privilege escalation is indicated. The attack requires local presence and code execution under a different user context.
Mitigation Recommendations
Linux kernel has a partial fix (CVE-2025-68788) that disables device file event generation, mitigating the most severe issues. Microsoft considers the Windows behavior by design and recommends limiting local access to trusted users and keeping systems updated. Administrators can enable protections documented by Microsoft for certain directory change notification scenarios. No patches or mitigations are currently available for Android or macOS. Users should follow vendor guidance and restrict untrusted local code execution. No urgent patching is mandated as the issue requires local attacker presence and does not expose file contents.
Windows, Linux, Android File Notification Systems Leak User Activity
Description
Researchers demonstrated that file-change notification systems in Windows, Linux, Android, and macOS can be exploited to leak user activity such as keystroke timing, browsing habits, and media events without elevated privileges. The attacks rely on monitoring file system events accessible to unprivileged users or apps, revealing metadata like file names and event timing rather than file contents. On Windows, monitoring the system drive root can expose file paths in other users' profiles, enabling website fingerprinting. Linux kernel mitigations partially address the most severe issues, but no patches exist for Android or macOS. Microsoft considers the behavior by design and not a vulnerability. No in-the-wild exploitation is known, and proof-of-concept code is publicly available.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
File-change notification features in major operating systems allow applications to receive alerts when files are created, modified, or deleted. Researchers at Graz University of Technology showed that these features can be abused by unprivileged users or apps to monitor other users on the same system. The attacks do not expose file contents but use file names and event timing to infer sensitive user activities such as keystroke timing (revealing typing rhythms), visited websites via browser data folders, and media events in apps like WhatsApp. On Linux, watching readable folders can leak events from protected files. On Windows, monitoring the root of the system drive reveals full paths of changed files across user profiles. The Linux kernel has been partially hardened (CVE-2025-68788) to reduce severity, but no fixes exist for Android or macOS. Microsoft states this behavior is by design and recommends standard security best practices. Researchers have not observed active exploitation in the wild but have published proof-of-concept code.
Potential Impact
The vulnerability allows an attacker with local code execution under a separate user account to monitor file system events and infer user activities such as keystroke timing, browsing history, and media file events without accessing file contents. This can lead to privacy breaches and credential harvesting via UI spoofing (demonstrated on KDE Plasma 6). The impact is limited to information disclosure of metadata and timing, not direct file content access. No remote exploitation or privilege escalation is indicated. The attack requires local presence and code execution under a different user context.
Mitigation Recommendations
Linux kernel has a partial fix (CVE-2025-68788) that disables device file event generation, mitigating the most severe issues. Microsoft considers the Windows behavior by design and recommends limiting local access to trusted users and keeping systems updated. Administrators can enable protections documented by Microsoft for certain directory change notification scenarios. No patches or mitigations are currently available for Android or macOS. Users should follow vendor guidance and restrict untrusted local code execution. No urgent patching is mandated as the issue requires local attacker presence and does not expose file contents.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/","fetched":true,"fetchedAt":"2026-09-25T11:02:47.482Z","wordCount":1455}
Threat ID: 6ab654d7f7a7c54106ad2fab
Added to database: 09/25/2026, 11:02:47 UTC
Last enriched: 09/25/2026, 11:02:53 UTC
Last updated: 09/26/2026, 02:51:31 UTC
Views: 39
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.