Graz University of Technology reveals file notification leaks in Windows, Linux, Android
Summary
Researchers at Graz University of Technology in Austria have revealed that file-change notification features in operating systems such as Windows, Linux, Android, and macOS can be exploited to monitor user activities, including keystrokes and web browsing. While the attacks do not expose actual file contents, the identification of file names and event timing allows for significant user activity reconstruction. Most attacks require the attacker to already have code running on the affected machine, but techniques demonstrated include monitoring folders to track file access or employing counterfeit prompts to capture credentials. Although the Linux kernel has received a partial fix (CVE-2025-68788), no patches have been released for Android or macOS, and Microsoft characterizes the Windows behavior as intentional and not a vulnerability. Proof-of-concept code for these attacks is publicly available on GitHub, but the researchers are not aware of any real-world exploitation.