New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS
Graz University of Technology researchers show file-notification APIs (inotify, ReadDirectoryChangesW, FSEvents) leak user activity across Linux, Windows, macOS without privileges.
Researchers at Graz University of Technology published 'File Notification Attacks,' showing OS file-notification services (inotify on Linux, ReadDirectoryChangesW on Windows, FSEvents on macOS) let unprivileged local processes surveil user behavior. Semi-automated templates identified terminal commands, keystroke timing (F1 93.1–100% for seven users), SSH pseudo-terminal activity (100% F1), website visits, printing, and USB/Bluetooth/VPN changes at 0.2–11.5ms resolution with under 0.21% CPU overhead. On Windows, watching C:\ exposed other users' paths and Firefox browsing across 975 top-1,000 sites at 97.8% F1; on Linux the team demonstrated a KDE Plasma 6 pkexec UI-redress attack and Firefox website fingerprinting at 87.9% F1. Microsoft called the behavior by design (EnforceDirectoryChangeNotificationPermissionCheck is disabled by default) and Linux shipped only a partial mitigation in early 2026.