Decades-old file notification flaws found in Android, Linux, macOS and Windows
Researchers at TU Graz found that file-notification subsystems (inotify, FileObserver, ReadDirectoryChangesW, FSEvents) leak system activity to unprivileged users. Attacks reach 93.1–100% keystroke accuracy on Linux and 97.8% website-fingerprinting accuracy on Windows. Microsoft called the behavior 'by design'; only Linux received a partial patch.
- Affected: inotify (Linux, 2005), FileObserver (Android, 2008), ReadDirectoryChangesW (Windows, 2000), FSEvents (macOS, 2007)
- Linux keystroke timing attacks hit 93.1–100% accuracy locally and 100% over SSH
- Watching C:\ on Windows reveals another user's Firefox visits at 97.8% accuracy
- Linux CVE-2025-68788 was partially fixed in December 2025; Android remains unpatched
Read next
Security