Research accepted at ACM CCS 2026 reveals side-channel vulnerabilities in file-notification systems across Linux, Android, Windows, and macOS. Attackers with read-only access can monitor file notifications to reconstruct user behavior, with platform-specific severe issues including Linux's inotify leaking keystroke timing, Android's FileObserver bypassing per-app storage isolation, and Windows reporting system-wide file paths regardless of permissions.
A proof-of-concept Android app demonstrates electromagnetic side-channel transmission using smartphone Class-D amplifiers to leak RF signals around 144 MHz (2-meter amateur radio band) by synthesizing inaudible 21 kHz ultrasonic pulses at maximum volume, enabling covert OOK/CW modulation without special permissions.
Researchers address the spectral mismatch problem in electromagnetic side-channel attacks by using injected EM carriers to shift low-frequency secrets (audio, power signals) into efficient leakage bands, enabling extraction of information that passive eavesdropping cannot easily capture.