Download Privacy Needle App

Type to search

Cybersecurity

File Notification Systems Leak User Activity Across Major Operating Systems

Share

Researchers at Graz University of Technology in Austria have demonstrated that file-change notification systems in Windows, Linux, Android, and macOS can be exploited to monitor user activity. These built-in features, which allow applications to receive alerts when files are created, modified, or deleted, can be abused to reconstruct sensitive information such as keystroke timing and browsing habits.

The notification systems typically require no elevated privileges, requiring only read access to the location being monitored. While the attacks do not expose the actual contents of files, the researchers found that file names and the timing of events are sufficient to infer significant user behaviour.

Impact Across Operating Systems

On Linux, the research highlighted several methods of surveillance. By monitoring device files that represent keyboard input, attackers can detect the timing of keystrokes. In tests involving seven typists, this method achieved an accuracy rate between 93.1% and 100% for detecting keystrokes. Additionally, researchers demonstrated website fingerprinting with 87.9% accuracy by observing which system fonts Firefox loads for specific web pages. The study also included a counterfeit authentication prompt attack on the KDE Plasma 6 desktop environment running on Wayland.

Android devices were also found to be susceptible. An application with no requested permissions can monitor the private storage folders of other apps. When tested against WhatsApp, this technique allowed researchers to identify when photos, videos, or documents were sent or received, as well as the names of those files and when they were subsequently deleted.

The Windows environment presented a distinct risk when a user monitors the root of the system drive. In such cases, Windows reports the full path of every changed file across the entire machine, including files within other users’ home directories. Using this method, researchers achieved 97.8% accuracy in identifying websites visited via Firefox, though accuracy was lower for Microsoft Edge at 48.5% due to its differing folder structure.

macOS appeared to be the most resilient, as monitoring is limited to globally readable files. However, researchers were still able to track application launches and changes to system settings.

Vendor Responses and Mitigations

The Linux kernel has already undergone partial hardening to prevent device files from generating access and modify events. This specific fix is associated with CVE-2025-68788.

Microsoft has stated that the observed Windows behaviour is by design. A company spokesperson noted that the process only reveals file names and paths within other user profiles rather than sensitive file contents. Microsoft advised customers to follow security best practices, such as limiting local access to trusted users.

The researchers noted that they are not currently aware of any instances where these techniques have been exploited in the wild. Proof-of-concept code for the file notification attack has been made available on GitHub.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.