Researchers at Austria’s Graz University of Technology have found decades-old flaws in the file notification systems built into Android, Linux, macOS and Windows that let an unprivileged local user infer what other people on the same machine are doing, without ever reading a byte of their files.
How the file notification systems leak data
The affected subsystems are inotify on Linux, in the kernel since 2005; FileObserver on Android, since 2008; ReadDirectoryChangesW on Windows, since 2000; and FSEvents on macOS, since 2007. Each exists so an application can be told when a file it cares about has been opened, changed, written to or deleted, rather than having to poll the disk itself. None of them hand over file contents. The problem, according to TU Graz doctoral student Sudheendra Raghav Neela, is that the events themselves form a pattern an attacker can read: “We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change,” he told The Register.
The basic design flaw is access control. Unprivileged users can query the file notification systems directly, and on Linux and Windows that access works even without read permission on the file being watched. The researchers, who also include Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast and Daniel Gruss, describe the work in a paper titled “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,” summarised at inoti.fyi.
What an attacker can do with the leak
Most of the attack scenarios need a local account on a machine that also has files readable by multiple users, and the researchers note that the list of globally readable files on a typical system is long. From there, file event timing supports inter-keystroke timing attacks that reconstruct what a victim is typing, including over an SSH session rather than just locally, plus website fingerprinting that reveals which sites someone has visited and UI redress attacks that can be used to steal credentials.
SecurityWeek’s reporting adds that the same technique extracts WhatsApp media events, meaning the timing of an app’s file writes can betray what a user is doing inside it even when the notification system was never meant to expose application-level activity.
The primary record, and how this compares to other 2026 disclosures
The vulnerability is tracked as CVE-2025-68788 in the National Vulnerability Database, which is the record to watch for vendor advisories and patch status rather than either outlet’s writeup. It’s also a useful contrast with the last vulnerability disclosure teqpost covered, the unauthenticated RCE in Orkes Conductor: that flaw was already being exploited over the network before a fix landed. This one needs local access first, which caps the blast radius, but its scope is wider by design, since inotify, FileObserver, ReadDirectoryChangesW and FSEvents sit underneath almost every desktop and mobile OS in use, some of them for over two decades.
Watch CVE-2025-68788 for the advisories that follow. None of the four platform vendors has a patch tied to it in the material published so far, and a side channel rooted in how a notification API is designed, rather than a single coding mistake, tends to take longer to close than a typical memory-safety bug.








