Researchers from Graz University of Technology disclosed file-notification attacks exploiting inotify on Linux to conduct keystroke-timing and UI-redress attacks, including credential harvesting via fake password windows on KDE. Linux kernel versions released in January provided partial mitigation.
File-notification systems on Linux, Android, Windows, and macOS leak sensitive user behavior through side channels. Attackers with only read permissions can monitor file access patterns to reconstruct user actions, with platform-specific vulnerabilities including keystroke timing inference on Linux, cross-app surveillance on Android, and cross-user website tracking on Windows.
Research accepted at ACM CCS 2026 reveals side-channel vulnerabilities in file-notification systems across Linux, Android, Windows, and macOS. Attackers with read-only access can monitor file notifications to reconstruct user behavior, with platform-specific severe issues including Linux's inotify leaking keystroke timing, Android's FileObserver bypassing per-app storage isolation, and Windows reporting system-wide file paths regardless of permissions.