File Notification Attacks Let Hackers Track Keystrokes and Website Visits on Linux, Windows and macOS
Researchers showed file-notification APIs can leak keystrokes and website visits on Linux, Windows, and macOS.
Researchers from Graz University of Technology presented File Notification Attacks at ACM CCS 2026. Unprivileged processes can abuse file-event APIs on Linux, Windows, macOS, and Android to infer keystroke timing, application launches, website visits, USB use, VPN activity, and printing. On Linux, monitoring /dev/input produced keystroke-detection F1 scores of 93.1% to 100%, and SSH pseudo-terminal monitoring reached 100% F1. On Windows, watching C:\ revealed other users' paths and identified Firefox visits to the top 1,000 sites at 97.8% F1; Linux font patterns classified the top 100 sites at 87.9% F1.
- Graz University presented the attacks at ACM CCS 2026.
- Linux /dev/input notifications leaked keystroke timing to unprivileged processes.
- Windows drive watches exposed other users' paths and Firefox site visits.
- Linux font-access patterns classified top websites at 87.9% F1.
- Microsoft called the Windows behavior intentional; Linux has only partial fixes.
Full article678 words · extracted from gbhackers.com · click to collapse
Researchers have disclosed a new class of cross-platform side-channel attacks that exploit file-notification mechanisms in Linux, Windows, macOS, and Android to infer sensitive user and system activities.
These attacks can expose details such as keystroke timing, application launches, website visits, USB usage, VPN activity, printing, and other behaviors, even when the attacker lacks administrative privileges.
The research, titled “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,” was presented at ACM CCS 2026 by researchers from Graz University of Technology.
The team found that file-event APIs, which are intended for legitimate monitoring, can be repurposed as invasive observation channels.
Abuse of File Monitoring APIs
Modern operating systems provide APIs that notify applications when files are opened, read, modified, created, deleted, or renamed. The affected mechanisms include:
Applications typically use these APIs to refresh file-manager views, synchronize content, scan files for malware, or detect document changes. However, the researchers demonstrated that an unprivileged attacker could monitor event patterns and correlate them with specific user actions.
The technique employs a two-stage template attack model. In the first stage, the attacker records filesystem events while performing known actions on their own machine, such as launching an application, browsing a website, typing text, connecting a USB device, or enabling a VPN.
These observations serve as templates. In the second stage, the attacker monitors matching events on a victim’s system to infer the corresponding activities.
Linux leaked the most detailed information. By monitoring the publicly readable `/dev/input` directory, a local unprivileged process could receive notifications triggered by activity on otherwise unreadable input-device files.

The researchers observed that a keyboard press generally produces two notifications: one for key-down and another for key-up activity. While this attack does not directly reveal which character was pressed, it can capture the timing between keystrokes, which may allow inference of typed text.
Testing involving seven users achieved keystroke-detection F1 scores between 93.1% and 100%. The researchers reported that 66.6% of observed events occurred within 1 ms of the actual keypress, while 71.6% fell within 4.5 ms.
The team also demonstrated a remote SSH scenario. By monitoring pseudo-terminal activity in `/dev/pts`, they were able to detect text-producing keypresses from a remote SSH user, achieving a reported 100% F1 score with an average timing deviation of 2.9 ms. Notably, this scenario did not include password prompts that suppress terminal echo.
Website Tracking on Windows and Linux
Windows posed a more direct privacy risk. The researchers found that an unprivileged user observing the `C:\` drive could receive notifications revealing complete paths for files in other users’ profile directories, which should not be accessible to the observer.
This enabled real-time tracking of browser storage activity. Firefox, for example, stores site-related data in directories containing website identifiers, allowing the researchers to identify visits across the top 1,000 websites with a 97.8% F1 score and no false positives.
Microsoft reportedly described this behavior as intentional, despite its privacy implications.
On Linux, website fingerprinting relied on a side channel instead of direct paths. Different websites triggered distinct access patterns involving system-wide font files located in `/usr/share/fonts/`.
Using these patterns, the researchers achieved an 87.9% F1 score when classifying visits to the top 100 websites in an open-world evaluation.
While macOS exposed less information than Linux and Windows, FSEvents still enabled monitoring of application launches, settings changes, printer activity, removable storage events, and certain connectivity actions.
The measured notification resolution averaged 11.48 ms, compared to sub-millisecond results observed on Windows and Linux.
The researchers recommend implementing stricter permission checks for file-event subscriptions. Although Linux has deployed partial fixes for device-file monitoring, other unreadable-file notification paths remain exposed.
For Windows, the team suggests preventing unprivileged users from monitoring entire drives and enforcing directory-level permission checks by default.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.