Researchers at Graz University of Technology disclosed decades-old side-channel weaknesses in file-notification mechanisms used by Android, Linux, macOS, and Windows. A local unprivileged user can monitor file-event metadata—not file contents—to infer sensitive activity including keystrokes, website visits, authentication prompts, application usage, and connected-device events. On Linux, the exposure involves the inotify filesystem-event interface, which reports monitored filesystem activity to user-space applications.
Linux received a partial mitigation for CVE-2025-68788 in December 2025, but researchers reported no Android mitigation. Microsoft said the Windows behavior is by design. Organizations should restrict untrusted local code execution and review applications that use broad filesystem monitoring, while platform vendors are urged to enforce stronger permissions or capabilities for file-event monitoring—particularly preventing whole-drive monitoring on Windows.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Microsoft's refusal to remediate the Windows filesystem-event behavior was reportedly associated with the 2026 Pwnie Award category for Lamest Vendor Response.
Linux kernel releases 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, and 6.18.3 partially addressed CVE-2025-68788. The patch stops generation of access and modify events for special files under /dev/.
Microsoft documented administrator-enableable protections for certain directory-change-notification file-path disclosure scenarios. The guidance predates the Graz University researchers' disclosure of the broader cross-user Windows file-event behavior.
Researchers from Graz University of Technology disclosed file-notification information-leakage findings to the Linux, Android, Windows, and macOS security teams between August and October 2025.
The CCS 2026 research-artifact repository documented additional proofs of concept, including inferring WhatsApp media arrivals on Android, Firefox browsing origins on Windows, and application installations or removals through macOS FSEvents. It also provided a deliberately vulnerable Debian VM for controlled validation of Linux inotify attacks.
The researchers reported that Android had not appeared to mitigate FileObserver's ability to bypass per-application FUSE storage isolation and expose metadata from private application folders.
Microsoft told the researchers that Windows reporting full file paths while monitoring the C:\ root directory, regardless of permissions and users, was undocumented behavior by design.
Graz University of Technology researchers identified side-channel flaws in Linux inotify, Android FileObserver, Windows ReadDirectoryChangesW, and macOS FSEvents that allow local users to infer sensitive activity from file-event metadata. Demonstrated attacks included keystroke timing, website fingerprinting, and credential-theft UI redress attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceopennet.ru
Open sourcecyberveille.ch
Open sourcetheregister.com
Open sourceman7.org
Open sourceman7.org
Open sourceinoti.fyi
Open sourceinoti.fyi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.