File change notifications leak data on Linux, Android and Windows
Researchers at Graz University of Technology showed that unprivileged processes and Android apps without permissions can use file change notifications to infer keystroke timing, browsing destinations and WhatsApp media activity. On Linux the flaw also enables a spoofed KDE Plasma 6 authentication screen to steal credentials.
- The attack reads no file contents, relying on paths and event timestamps
- On Windows, site names may leak directly through browser storage paths
- The Linux fix for CVE-2025-68788 is only a partial mitigation
- Windows requires manually enabling EnforceDirectoryChangeNotificationPermissionCheck
Read next
Software