• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Software / Decades-old flaw in file notification systems spans four OSes

Decades-old flaw in file notification systems spans four OSes

byLotfi Ben Taleb
September 25, 2026
in Software
Reading Time: 2 mins read
Laptop showing terminal text beside a floppy disk, floppy drive, and CDs, with cables on a concrete floor
Share on Facebook
Share on Twitter

Researchers at Austria’s Graz University of Technology have found decades-old flaws in the file notification systems built into Android, Linux, macOS and Windows that let an unprivileged local user infer what other people on the same machine are doing, without ever reading a byte of their files.

How the file notification systems leak data

The affected subsystems are inotify on Linux, in the kernel since 2005; FileObserver on Android, since 2008; ReadDirectoryChangesW on Windows, since 2000; and FSEvents on macOS, since 2007. Each exists so an application can be told when a file it cares about has been opened, changed, written to or deleted, rather than having to poll the disk itself. None of them hand over file contents. The problem, according to TU Graz doctoral student Sudheendra Raghav Neela, is that the events themselves form a pattern an attacker can read: “We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change,” he told The Register.

The basic design flaw is access control. Unprivileged users can query the file notification systems directly, and on Linux and Windows that access works even without read permission on the file being watched. The researchers, who also include Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast and Daniel Gruss, describe the work in a paper titled “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,” summarised at inoti.fyi.

What an attacker can do with the leak

Most of the attack scenarios need a local account on a machine that also has files readable by multiple users, and the researchers note that the list of globally readable files on a typical system is long. From there, file event timing supports inter-keystroke timing attacks that reconstruct what a victim is typing, including over an SSH session rather than just locally, plus website fingerprinting that reveals which sites someone has visited and UI redress attacks that can be used to steal credentials.

SecurityWeek’s reporting adds that the same technique extracts WhatsApp media events, meaning the timing of an app’s file writes can betray what a user is doing inside it even when the notification system was never meant to expose application-level activity.

The primary record, and how this compares to other 2026 disclosures

The vulnerability is tracked as CVE-2025-68788 in the National Vulnerability Database, which is the record to watch for vendor advisories and patch status rather than either outlet’s writeup. It’s also a useful contrast with the last vulnerability disclosure teqpost covered, the unauthenticated RCE in Orkes Conductor: that flaw was already being exploited over the network before a fix landed. This one needs local access first, which caps the blast radius, but its scope is wider by design, since inotify, FileObserver, ReadDirectoryChangesW and FSEvents sit underneath almost every desktop and mobile OS in use, some of them for over two decades.

Watch CVE-2025-68788 for the advisories that follow. None of the four platform vendors has a patch tied to it in the material published so far, and a side channel rooted in how a notification API is designed, rather than a single coding mistake, tends to take longer to close than a typical memory-safety bug.

Tags: linuxvulnerabilitywindows
Previous Post

Google Maps adds traffic light and stop sign icons on Android Auto

Next Post

Intel Arc graphics driver update adds game support, bugs remain

Related Posts

Close-up of a green circuit board with black surface-mount chips and a white connector
Software

New Spectre v2 attack recovers Linux root password hashes

September 30, 2026
Woman taps a phone in a blue case against a wireless card payment terminal on a wooden counter
Software

Apple Pay launches in India, but only with Axis Bank cards

September 30, 2026
Smartphone in a car dashboard mount showing Google Maps overview of New York with an Explore Nearby panel
Software

Google Maps adds traffic light and stop sign icons on Android Auto

September 25, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

September 28, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Intel Arc B580 graphics card resting against its retail packaging boxes

Intel Arc graphics driver update adds game support, bugs remain

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply