Researchers from Graz University of Technology disclosed file-notification attacks exploiting inotify on Linux to conduct keystroke-timing and UI-redress attacks, including credential harvesting via fake password windows on KDE. Linux kernel versions released in January provided partial mitigation.
Research accepted at ACM CCS 2026 reveals side-channel vulnerabilities in file-notification systems across Linux, Android, Windows, and macOS. Attackers with read-only access can monitor file notifications to reconstruct user behavior, with platform-specific severe issues including Linux's inotify leaking keystroke timing, Android's FileObserver bypassing per-app storage isolation, and Windows reporting system-wide file paths regardless of permissions.