File-Notification Systems Leave Windows, Linux, Android and macOS Vulnerable
en-GBde-DEes-ESfr-FR

File-Notification Systems Leave Windows, Linux, Android and macOS Vulnerable

28/09/2026 TU Graz

A research team at TU Graz has demonstrated that the file notification systems of various operating systems can be exploited to spy on users' activities and forge password prompts.

Researchers at the Institute of Information Security at Graz University of Technology (TU Graz) have uncovered security risks in the file notification systems of the widely used operating systems Windows, Linux, Android and macOS. Through so-called side-channel attacks, system-wide changes to files, keystrokes and visited websites can be tracked, and password prompt windows can be spoofed to intercept password entries. The researchers summarised their findings in the paper “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS, which they have published on a dedicated website: https://inoti.fyi

A workaround via readable folders

File notification systems monitor whether files are created, deleted, opened, closed or modified, and automatically deliver system notifications so that applications or the system can react to the change. The research team discovered that apps or other users on the same system can monitor these notifications, even without administrator rights. This makes it possible to track what other users on the system are doing. Read access to specific folders is all that is required to read all files stored in a folder, as well as the subfolders and their contents – even if they do not actually permit read access. One thing that applies to all systems: file contents cannot be read; only file names and changes can be detected. However, this is sufficient to monitor user, system and application behaviour.

Browsing history can be tracked

The research team uses case studies to illustrate what such attacks could actually look like. To bypass the read-access restrictions on folders and files in Windows, the researchers simply tapped into the file notification system of the parent directory that was not read-protected. Using notifications of the main directory C:\, the researchers discovered that it was possible to track all file system events in all subfolders, including filenames. As browsers such as Firefox create a separate folder for every visited website that requires local storage, with the folder name containing the name of the website, attackers can easily trace where users have been on the internet in real time.

Intercepting keystrokes and passwords

On Linux, the researchers used the “inotify” file notification system to track keystrokes within a read-protected file. Although Linux initially prevented direct monitoring on the file, it became possible as it was located in a readable folder, which allowed to spy on everything in it via the notification system. This made the keystrokes in the read-protected file visible. While the team could not see which keys had been pressed, inter-keystroke timing attacks have been around for more than two decades. Thanks to knowledge accumulated over the years, the time elapsing between individual keystrokes now reveals plenty of information.

On KDE Plasma, a popular desktop environment on Linux, the security researchers managed to overlay fake password entry windows on top of the genuine ones as soon as an authentication prompt was called up, even when the secure Wayland display server protocol was in use. To achieve this, they monitored the executable file of the “polkit” programming interface, which carries out authorisation checks. As soon as they detected an access attempt that opened a password window, the test attackers superimposed a fake password window over it so that users would enter their details there and reveal their passwords.

Data exchange via WhatsApp

On Android, the “FUSE” system is actually intended to prevent apps from accessing each other's folders. Not even the folders’ contents should be visible. However, an app without special permissions was still able to spy on activity within another app’s folder by using file notifications as a workaround. The team was thus able to observe whether images, videos and files were arriving in, being sent from or deleted from WhatsApp's folders. The researchers emphasize that they could not see the contents of these files, but they could read the file names, which might reveal something about the file’s contents and the behaviour of the user using the Android phone.

While macOS exposes the least amount of information via globally readable files, the team found that user, application, and system behaviour can still be tracked, pointing out that the macOS “FSEvents” application programming interface (API) still yields meaningful insight into user activity.

As is customary in such cases, the research team alerted the relevant teams at Linux, KDE, Android, Microsoft and Apple to the potential vulnerabilities at an early stage so they could respond before the paper was published. In collaboration with the Linux security team, patches have already been rolled out to address some of the vulnerabilities.

Publication: File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS

Authors: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast and Daniel Gruss

Available at: https://inoti.fyi
Archivos adjuntos
  • Image source: Brinda Neela; CC BY 4.0; https://inoti.fyi/
28/09/2026 TU Graz
Regions: Europe, Austria
Keywords: Applied science, Computing, Technology

Disclaimer: AlphaGalileo is not responsible for the accuracy of content posted to AlphaGalileo by contributing institutions or for the use of any information through the AlphaGalileo system.

Testimonios

We have used AlphaGalileo since its foundation but frankly we need it more than ever now to ensure our research news is heard across Europe, Asia and North America. As one of the UK’s leading research universities we want to continue to work with other outstanding researchers in Europe. AlphaGalileo helps us to continue to bring our research story to them and the rest of the world.
Peter Dunn, Director of Press and Media Relations at the University of Warwick
AlphaGalileo has helped us more than double our reach at SciDev.Net. The service has enabled our journalists around the world to reach the mainstream media with articles about the impact of science on people in low- and middle-income countries, leading to big increases in the number of SciDev.Net articles that have been republished.
Ben Deighton, SciDevNet
AlphaGalileo is a great source of global research news. I use it regularly.
Robert Lee Hotz, LA Times

Trabajamos en estrecha colaboración con...


  • The Research Council of Norway
  • SciDevNet
  • Swiss National Science Foundation
  • iesResearch
Copyright 2026 by DNN Corp Terms Of Use Privacy Statement