New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A cross-platform side-channel attack that abuses file-notification services to monitor user activity on Linux, Windows and macOS. The technique turns inotify, ReadDirectoryChangesW, and FSEvents, which alert applications when files are changed, into a surveillance mechanism requiring no elevated privileges.

The study, “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,” comes from researchers at Graz University of Technology.

Rather than exploiting memory corruption, the attack observes legitimate operating-system notifications and correlates their timing and file paths with recognizable behavior.file-notification-attacks.pdf

According to research published by Graz University of Technology, researchers built a semi-automated templating process that records filesystem events while actions are performed.

The templates can identify terminal commands, keyboard and mouse input, website visits, web-server activity, printing, virtual machines, containers, Bluetooth and VPN changes, and USB-device interaction.

New File Notification Attack

Tests achieved resolution ranging from 0.2 milliseconds to 11.5 milliseconds, while monitoring imposed no more than 0.21% CPU overhead in the researchers’ measurements.

File notification attack templating and attack workflow (Image Source: Inoti)

Linux exposed fine-grained signals because inotify reports file-access events. By watching readable parent directories, an unprivileged account could receive notifications involving files it could not directly read, including entries under /dev.

This enabled local keystroke-timing detection with F1 scores between 93.1% and 100% for seven users. Monitoring pseudo-terminal activity over SSH achieved a 100% F1 score, although password fields that suppress terminal echo were not observable.

Inotify event throughput and capture rate benchmark (Image Source: Inoti)

The team demonstrated an authentication UI-redress attack against KDE Plasma 6 on Wayland. Notifications revealing execution of PolicyKit’s pkexec component let malicious code time a counterfeit window over the legitimate prompt.

Firefox font-access patterns enabled open-world fingerprinting of the top 100 websites with an 87.9% F1 score.file-notification-attacks.pdf

Windows presented the most direct privacy leak. An unprivileged user watching the root of the C: drive could receive paths for files inside another user profile, despite lacking permission to read those directories.

Browser storage paths exposed visited domains, allowing Firefox website monitoring for 975 responsive sites in a top-1,000 list with a 97.8% F1 score and no false positives. Edge scored 48.5% because it produced fewer site-specific storage directories.

On macOS, FSEvents disclosed less information because private directories could not be monitored across users. Shared system files still revealed application launches, settings changes, printing, network-cable activity, external storage, Bluetooth-device changes, and VMware virtual-machine state.

Its average latency was 11.48 milliseconds, the slowest of the three platforms but still useful for behavioral monitoring. The attack requires malicious code to run as an unprivileged local user, so it is not a standalone remote compromise.

The danger is stealthy post-compromise surveillance: malware could infer sensitive behavior without reading protected content, injecting into applications or using hardware-specific cache attacks.

False interpretations remain possible when different activities generate similar filesystem patterns. Researchers disclosed the findings to Linux, Microsoft, Apple and KDE in October 2025. Linux deployed a partial mitigation for device files in early 2026, but the broader unreadable-file bypass remained.

Microsoft classified the behavior as by design; a related Windows policy, EnforceDirectoryChangeNotificationPermissionCheck, can restrict unauthorized path disclosure but is disabled by default, the paper noted.

The researchers recommend permission checks that distinguish owned, readable and protected files, plus tighter limits on whole-drive monitoring. The findings show filenames, access timing and notification metadata should be treated as sensitive telemetry.

Sandboxing untrusted applications, separating service accounts, applying OS updates, and enabling stricter notification-permission controls can reduce exposure while vendors redesign these APIs.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS appeared first on Cyber Security News.