Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    APOD: 2026 September 27 – Andromeda Before and After Photoshop

    September 27, 2026

    Siri AI finally starts to make sense

    September 27, 2026

    Gemini not generating images [Fix]

    September 27, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Windows, Linux, Android File Notification Systems Leak User Activity
    Windows, Linux, Android File Notification Systems Leak User Activity
    Cybersecurity

    Windows, Linux, Android File Notification Systems Leak User Activity

    The Tech GuyBy The Tech GuySeptember 27, 2026No Comments4 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Researchers at Graz University of Technology in Austria show that the file-change notification features built into Linux, Android, Windows, and macOS can be abused to monitor other users on the same system, from the rhythm of their typing to the websites they visit.

    Advertisement

    Linux, Windows, macOS, and Android let applications ask to be alerted when files are created, modified, or deleted. Text editors, file managers, sync clients, and antivirus products are among the programs that use this capability. It requires no elevated privileges, only read access to the location being watched. 

    The attacks never expose file contents, but the researchers demonstrated that file names and the timing of events are enough to reconstruct user, application, and system activity. Most of the attacks require an adversary who can already run code on the machine under a separate account. On Android, it would be an app that requests no permissions. 

    On Linux, a user who is denied permission to watch a protected file can still receive its events by watching the folder that contains it, as long as that folder is readable. Applied to the device files that represent keyboard input, this reveals when a user presses a key, though not which key. 

    Research going back more than two decades has shown that the intervals between keystrokes can help infer what is being typed. In tests with seven typists, the attack reliably detected keystrokes, scoring between 93.1% and 100% on a standard accuracy measure. Input that produces no on-screen text, such as a hidden sudo password, is not captured.

    Other Linux attacks include website fingerprinting based on which system fonts Firefox loads for a page. This identified sites from the top 100 with an accuracy of 87.9%. The researchers also demonstrated a fake password prompt attack on the KDE Plasma 6 desktop running on Wayland. A malicious process running as the victim detects when the real authentication dialog is about to appear and draws a counterfeit over it to capture credentials. 

    Advertisement. Scroll to continue reading.

    The researchers carried out their Android evaluations on a Google Pixel and Samsung Galaxy phones. They found that an app with no permissions can watch another app’s private storage folder. 

    In tests against WhatsApp, the technique revealed when photos, videos, and documents were received or sent, along with their file names. It also revealed when that media was later deleted.

    The most serious Windows issue arises when a user monitors the root of the system drive. Windows then reports the full path of every file changed anywhere on the machine, including inside other users’ home directories that the monitoring account cannot read. 

    Firefox stores data for many websites in folders named after the site, so an unprivileged user can see in real time which sites another user is visiting. Across the top 1,000 websites, the researchers achieved 97.8% accuracy for Firefox and 48.5% for Edge, which creates folders for far fewer sites. 

    macOS leaks the least because only globally readable files can be monitored, but the researchers could still track application launches, app interactions, and settings changes. 

    No patches for most attack scenarios

    The Linux kernel has been partially hardened so that device files no longer generate access and modify events, which the researchers say addresses the most severe issues. That fix is tracked as CVE-2025-68788. The researchers list no fixes for Android or macOS.

    Microsoft told the researchers that the Windows behavior is by design, and that it reveals only file names and paths in another user’s profile directory, not file contents or sensitive data. 

    In a statement to SecurityWeek, a Microsoft spokesperson said: 

    “We thank the researcher for reporting this behavior. We investigated and determined that this is not a security vulnerability. The technique requires an attacker to already have the ability to run code locally on a device under a separate user account and does not provide access to file contents. Customers can help protect themselves by following security best practices, including limiting local access to trusted users, and keeping systems up to date.”

    Microsoft also pointed to protections it documented in April 2025 for certain file-path disclosure scenarios involving directory change notifications, which administrators can enable. 

    Apple and Google have not responded to SecurityWeek’s request for comment.

    The researchers say they are not aware of in-the-wild exploitation. Proof-of-concept code for the file notification attack has been published on GitHub. 

    Related: Old Attack, New Speed: Researchers Optimize Page Cache Exploits

    Related: Researchers Demo New Claude Code Attack That Hijacks Developer Machines

    Related: A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    September 27, 2026

    Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

    September 27, 2026

    China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    September 26, 2026

    New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    September 26, 2026

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    September 26, 2026

    CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

    September 26, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    APOD: 2026 September 27 – Andromeda Before and After Photoshop

    September 27, 2026

    Siri AI finally starts to make sense

    September 27, 2026

    Gemini not generating images [Fix]

    September 27, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.