
Researchers from the Technical University of Graz have discovered vulnerabilities in the file notification systems on Android, Linux, macOS, and Windows. According to graduate student Sudeendra Raghav Neela, "old vulnerabilities" affect the subsystems that each modern operating system uses to notify applications of file changes. Issues were found in inotify (Linux, since 2005), ReadDirectoryChangesW (Windows, since 2000), FSEvents (macOS, since 2007), and FileObserver (Android, since 2008).
These subsystems do not disclose file contents, but their events act as a side channel for data transmission. An attacker can conduct attacks based on keystroke intervals – locally (accuracy 93.1–100%) and via SSH (100%) – site fingerprinting attacks (87.9% on the top 100 most popular) and spoofing the authentication window on KDE Plasma 6 under Wayland.
The Linux vulnerability (CVE-2025-68788) was partially fixed in December 2025 in kernel versions 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, and 6.18.3. The update blocks "access" and "modify" events for files in the /dev/ directory. On Android, FileObserver bypasses the FUSE layer: an application without permissions can monitor the private WhatsApp folder and see when photos, videos, and documents are sent or received by file name and timestamp. No fixes for Android are available yet.
macOS provided the least information – no bypasses for reading private folders were found. However, FSEvents allowed tracking changes in .plist files: sound, power, Bluetooth, printer settings, DNS changes, volume mounting, application installation, and removal. On Windows, monitoring the root directory of the C drive reveals the full path of each file regardless of permissions – enough to track sites in Firefox with 97.8% accuracy. "Microsoft informed us that this is 'by design' and that it is an undocumented feature. This response was nominated for the most unconvincing vendor reaction at the Pwnie Awards 2026," Neela stated.





