File-notification attacks leak keystrokes and browsing
TU Graz shows inotify, ReadDirectoryChangesW, FSEvents and Android FileObserver leak other users' activity. Which fixes exist and what to switch on.
By Yaali. September 30, 2026, 6 min read, Vulnerabilities, Patching, Windows.
Researchers at Graz University of Technology (TU Graz) have shown that the file-change notification services built into Linux, Windows, macOS and Android leak what other users on the same machine are doing. An ordinary, unprivileged account can watch a directory it is allowed to list and learn when another user types, which websites they visit in Firefox, which programs they start and, on Android, when media arrives in another app's private folder. The attacker never reads a single file.
The paper, "File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS", will be presented at ACM CCS 2026 in November, and proof-of-concept code is on GitHub. Fixes are uneven. Linux has a partial kernel fix, CVE-2025-68788. Windows has a mitigation that ships switched off. Android and macOS have none. That matters most wherever people share a machine or where untrusted code runs under a separate account: terminal servers, virtual desktops, shared Linux build and jump hosts, and phones with apps you did not vet.

How it works
Every desktop and mobile operating system has an API that tells a program when files change, so editors can reload a file, sync clients can upload it and file managers can refresh a window. On Linux that is inotify, on Windows ReadDirectoryChangesW, on macOS FSEvents and on Android FileObserver. Each one lets an account subscribe to any directory it has permission to read, and each one then reports events about the files inside it.
The flaw is the gap between the permission checked and the information returned. Being allowed to list a directory is treated as enough to receive events about its children, even children the watcher cannot open. An event carries a file name and a moment in time. Repeated thousands of times, those names and timestamps become a record of someone else's activity. The team recorded every file event while doing ordinary tasks and built templates for terminal commands, keyboard and mouse input, browsing, printing, virtual machines and Docker containers, Bluetooth, network and VPN changes, and USB devices.
On Linux, /dev/input is readable as a directory, while the keyboard device files inside it are not. Watching the directory with inotify still produced an access event on every key press. The timing between key presses is the classic input for inferring what was typed. The researchers scored 93.1 to 100 percent keystroke accuracy across seven typists locally, and 100 percent over an SSH session. They also showed a credential attack on KDE Plasma: by watching /usr/bin/pkexec, an attacker can tell the instant a Polkit password prompt opens and place a fake password window over it.
On Windows, a normal user who watches the root of C:\ receives the full paths of files changing inside other users' profiles, although they cannot open those folders. Firefox writes a cache folder named after the site for 95.7 percent of the sites tested, and Edge for 32 percent. Watching for those names, the researchers identified Firefox visits across 975 responsive sites from a top-1,000 list with a 97.8 percent F1 score (a measure combining hit rate and precision) and no false positives.
On Android 16, tested on Pixel and Samsung phones, an app with no permissions at all used FileObserver to get around the FUSE layer that is meant to keep apps out of each other's storage. It could see files arrive in, be sent from and be deleted from WhatsApp's media folders. macOS leaked the least, because FSEvents only reports changes to files the watcher can read, but printing, Bluetooth changes, app installs and removals, and some app launches still showed up.
What attackers are doing
No exploitation in the wild has been reported, according to the researchers and SecurityWeek. The attack needs code already running on the machine under some account, which is why vendors have been slow to call it a vulnerability. Microsoft told SecurityWeek it "determined that this is not a security vulnerability", because the attacker needs local code execution and file contents are not exposed. Apple and Google did not respond to SecurityWeek's questions.
On a shared Remote Desktop Session Host or Linux server, every user already has local code execution. On a phone, any installed app does. The proof-of-concept code is public.
What to do

Linux: update the kernel
The fix for CVE-2025-68788, the commit "fsnotify: do not generate ACCESS/MODIFY events on child for special files", stops a directory watcher from getting access and modify events when someone reads or writes a device file inside it. That closes the /dev/input keystroke route. It landed in stable kernels 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65 and 6.18.3 in January 2026. One CVE tracker lists 6.12.64 for the 6.12 branch, so go by your distribution's advisory for the exact package version.
To check a host, run inotifywait -m -e access,modify /dev/input as an unprivileged user and type in another session. A patched kernel stays silent. The fix is partial: regular files in any directory a user can list still produce events, so the wider tracking still works.
Windows: turn on the permission check
Since the April 8, 2025 updates, Windows has had a fix, documented in KB5058189 for CVE-2025-21197 and CVE-2025-27738, that checks the watcher's FILE_LIST_DIRECTORY right on the parent folder of each changed file before it reports the change. Microsoft ships it disabled "to prevent any unexpected security risks or application disruption". To turn it on, create the DWORD EnforceDirectoryChangeNotificationPermissionCheck with value 1 under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies or HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem. The Policies key wins if both are set. It covers Windows 10 1607 and later, Windows 11 and Windows Server 2008 to 2025.
Test it first with programs that rely on change notifications: file sync clients, backup agents, antivirus and endpoint agents, and developer tools that watch folders. Roll it out to multi-user hosts first, meaning session hosts, virtual desktop pools and shared admin servers, and push it through Group Policy Preferences or Intune so it stays set.
KDE Plasma: keep password prompts on top
The researchers recommend setting the Polkit password window to "Keep above other windows" with a KWin window rule, so a fake window cannot sit over it. The KDE security team noted that focus-stealing prevention is not a security boundary, so do not rely on it.
Android and macOS: no fix yet
There is nothing to install. On Android, keep sideloading off, limit managed devices to apps from an allowlist. On shared Macs, keep separate accounts and do not install untrusted software.
Where this leaves shared machines
Checking whether you were watched is hard, because the attack only subscribes to events and reads nothing. On Linux, find /proc/[0-9]*/fd -lname 'anon_inode:inotify' 2>/dev/null lists every process holding an inotify instance by process ID; look for programs you do not recognise, and read /proc/<pid>/fdinfo/<fd> to see the inode numbers they watch. On Windows there is no built-in log of who calls ReadDirectoryChangesW, so the practical control is who can run code on the host at all.
The lesson for hardening is that "can list the directory" is itself a disclosure. Home directories and profile folders that other users can list, still the default on many Linux servers, now hand out activity data as well as file names.
Our hardening work covers shared host baselines, registry policy and kernel patch levels, and our mobile penetration testing checks what an unprivileged app can see on your managed devices. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: TU Graz research site (inoti.fyi), Help Net Security, SecurityWeek, LWN.net, TechXplore, Cyber Security News, Microsoft KB5058189, OpenCVE: CVE-2025-68788.
Read next
- 974 fixes in one Patch Tuesday: what to patch first
- Chrome 154 and Firefox 157 fix 108 flaws: patch and relaunch
- Cisco SD-WAN Manager flaw gives admin API with no login
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.