This post is also available in:
Operating systems constantly monitor files so applications can react when something changes. A program may need to know when a file is created, modified or deleted, for example. But researchers have found that these routine notifications can also become an unexpected surveillance channel, revealing user activity even when an attacker cannot read the files themselves.
Researchers at Graz University of Technology identified weaknesses in file-notification systems across Windows, Linux, Android and macOS. Their experiments show that an application or another user on the same system can potentially monitor file activity without administrator privileges.
The problem stems from how file notifications interact with permissions.
According to TechXplore, in some cases, an attacker only needs read access to a parent folder to observe notifications generated by files and subfolders inside it, even when those deeper locations are themselves protected from reading. The attacker cannot see the contents of the files, but can learn their names and when they are opened, created, changed or deleted.
That metadata can reveal surprisingly detailed information.
On Windows, researchers monitored notifications from the main C:\ directory and were able to observe file-system events occurring within its subfolders. Because creates folders associated with websites that use local storage, the team could use those events to determine which websites a person visited in real time.
On Linux, the researchers demonstrated another side channel using the inotify notification system. They monitored activity involving a protected file through its readable parent folder and extracted the timing between keystrokes. While the technique did not reveal which individual keys were pressed, timing patterns can provide information about what a person is typing.
The team also demonstrated a more direct credential threat on KDE Plasma. By watching the executable associated with authorization checks, researchers could detect when a legitimate password prompt appeared and immediately place a fake password window over it, potentially capturing the user’s credentials.
Android showed a similar permissions gap. Although its FUSE system is intended to isolate applications’ folders, an app without special permissions could monitor file activity inside another application’s directory. Researchers used this to observe when WhatsApp images, videos and files were received, sent or deleted, including their filenames but not their contents.
macOS leaked less information, although its FSEvents API could still reveal meaningful patterns about application, system and user behavior.
These findings also have implications for government and defense devices. Metadata about websites, communication activity or authentication events can provide useful intelligence even without exposing the underlying files, making side-channel leakage relevant wherever sensitive systems share applications or users.
The researchers notified the affected development teams before publication. Working with the Linux security team, patches have already been released for some of the identified issues.
The research highlights an often-overlooked security principle: protecting the contents of a file is not always enough. Sometimes, simply knowing when it changes, what it is called and which application touched it can reveal far more than intended.
The research was published here.


























