Security teams have long treated file-change notifications as an ordinary operating-system feature used by editors, sync clients, and antivirus tools. The operational shift is that the same built-in APIs can now be used by an unprivileged local process to observe another user's activity without elevated privileges. Researchers at Graz University of Technology showed that file names and event timing are enough to reconstruct typing rhythm, website visits, and application activity. The development driving the change is the publication of proof-of-concept code and the partial Linux kernel fix tracked as CVE-2025-68788. For readers, the concern is not that file contents are exposed, but that ordinary local access can turn routine file notifications into a monitoring channel. The change is operational: routine file notifications, once treated as a background convenience, are now a monitoring channel that local processes can use to infer activity. This matters because many systems are shared, and local access is often broader than teams assume.
WHAT HAPPENED
Researchers at Graz University of Technology demonstrated that file-change notification features in Linux, Android, Windows, and macOS can be abused to monitor other users on the same system. The attacks require no elevated privileges, only read access to the location being watched. The attacks do not expose file contents, but file names and event timing can reveal user, application, and system activity. Text editors, file managers, sync clients, and antivirus products are among the programs that use this capability. Most of the attacks require an adversary who can already run code on the machine under a separate account. On Android, it would be an app that requests no permissions. On Linux, a user who cannot read a protected file can still receive its events by watching the readable folder that contains it. Applied to keyboard input device files, this reveals when a key is pressed, though not which key. Keystroke timing tests scored between 93.1% and 100% accuracy. Input that produces no on-screen text, such as a hidden sudo password, is not captured. The researchers also showed a fake password prompt attack on the KDE Plasma 6 desktop running on Wayland: a malicious process detects when the real authentication dialog is about to appear and draws a counterfeit over it to capture credentials. On Linux, website fingerprinting based on which system fonts Firefox loads for a page identified sites from the top 100 with 87.9% accuracy. On Android, an app with no permissions can watch another app's private storage folder. In tests on a Google Pixel and Samsung Galaxy, the technique revealed when WhatsApp photos, videos, and documents were received or sent, and when that media was later deleted. On Windows, monitoring the root of the system drive reports the full path of every file changed anywhere on the machine, including inside other users' home directories. Firefox stores data for many websites in folders named after the site, so an unprivileged user can see in real time which sites another user is visiting. Across the top 1,000 websites, the researchers achieved 97.8% accuracy for Firefox and 48.5% for Edge. macOS leaks the least because only globally readable files can be monitored, but the researchers could still track application launches, app interactions, and settings changes. The Linux kernel has been partially hardened so that device files no longer generate access and modify events; that fix is tracked as CVE-2025-68788. Microsoft said the Windows behavior is by design and pointed to documented protections. The researchers reported no known in-the-wild exploitation, and proof-of-concept code has been published on GitHub.
HOW THE STORY DEVELOPED
The story developed from the researchers' demonstration across four operating systems. They first showed that file notifications can be used to infer activity. They then published proof-of-concept code on GitHub. The Linux kernel has been partially hardened so that device files no longer generate access and modify events; that fix is tracked as CVE-2025-68788. Microsoft responded that the Windows behavior is by design and pointed to protections it documented in April 2025 for certain file-path disclosure scenarios. Apple and Google have not responded to requests for comment. The researchers reported no known in-the-wild exploitation. The Android and macOS results remain without listed fixes, so the operational question is which local processes are allowed to watch files and which users can run code on shared systems. The research also shows that ordinary local access can be enough to reconstruct behavior, which changes how organizations should think about local isolation.
WHY IT MATTERS
Documented facts: the attacks require local access, do not expose file contents, and have no known in-the-wild exploitation. The broader implication is that operating-system file notifications can act as a side channel for cross-user monitoring. For organizations, this means local isolation is not a complete security boundary. A process running under a separate account can still observe file names and event timing. For individuals, it means shared computers and shared mobile devices need review of which local processes can watch files. The Linux fix reduces the most severe Linux issues, but the researchers listed no fixes for Android or macOS, and Microsoft treats the Windows behavior as by design. The practical significance is that file notifications, once seen only as a convenience feature, now need to be treated as a potential monitoring surface in multi-user environments. The research also shows that ordinary local access can be enough to reconstruct behavior, which changes how organizations should think about local isolation.
WHAT IT MEANS FOR YOU
1. If you share a computer with family or coworkers, an unprivileged local process can watch file events and infer what you type and which sites you visit.
2. If you install apps from untrusted sources, a malicious local app could use file notifications to observe your activity without asking for special permissions.
3. If you use Android, an app with no permissions can watch another app's private storage and see when media is received, sent, or deleted.
4. If you manage a shared Linux or Windows machine, review which local processes can access file notifications and limit unnecessary local access.
5. If you use a Linux desktop with KDE Plasma 6 on Wayland, be aware that a malicious local process could draw a fake password prompt over the real authentication dialog.
WHAT ORGANIZATIONS SHOULD CONSIDER
1. Inventory local processes that use file-change notifications and restrict them to trusted software.
2. On Linux, apply the CVE-2025-68788 hardening where available.
3. On Windows, enable the documented protections for file-path disclosure scenarios.
4. For Android, review app permissions and avoid installing untrusted apps.
5. For macOS, monitor local processes and limit local access, since no fix was listed.
6. For shared systems, restrict which users can run code and which folders are readable by unprivileged processes.
WHAT TO WATCH NEXT
Watch for Apple and Google responses, additional Linux kernel updates, and whether the published proof-of-concept code is used in attacks. The Linux fix addresses the most severe Linux issues, but Android and macOS still have no listed fixes. Microsoft's by-design position means organizations should track whether its documented protections are enabled and whether new monitoring scenarios appear. Because the researchers reported no known in-the-wild exploitation, the next signal to monitor is whether any of the published techniques are observed in real systems. Also watch whether Apple or Google release fixes for Android and macOS, and whether Linux distributions ship the CVE-2025-68788 hardening more broadly.