A new security study has uncovered a privacy concern affecting Linux, Windows, and macOS. Researchers found that attackers could use normal file-notification features to monitor user activity without needing administrator privileges.
File-notification systems are designed to help applications know when files or folders change. However, researchers discovered that the information they provide can also reveal useful clues about what a user is doing.
The research was conducted by researchers at Graz University of Technology. Their study, titled “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,” explores how these signals can be used as a side channel.
How the File Notification Attack Works
Linux, Windows, and macOS use different technologies to monitor file-system changes. These include inotify on Linux, ReadDirectoryChangesW on Windows, and FSEvents on macOS.
These services are not vulnerabilities by themselves. They are legitimate features used by applications to respond to changes in files and folders.
The problem is that notifications can contain information such as file paths, timing, and activity patterns. By collecting this information and comparing it with previously recorded examples, malicious software can potentially identify what a user is doing.
Researchers created a semi-automated system that records file-system activity while different actions are performed. These recordings can then be used as templates to recognize similar activity later.
The study found that these patterns could reveal activities including terminal commands, keyboard and mouse input, website visits, printing, virtual machines, containers, VPN changes, Bluetooth activity, and USB-device connections.
The monitoring also had a very small effect on system performance, with the researchers measuring CPU overhead of no more than 0.21% in their tests.
Linux and Windows Show Significant Information Leakage
Linux produced some of the most detailed activity signals in the study. Researchers found that an unprivileged user could receive certain file notifications even when they could not directly read the related files.
This information was enough to identify keystroke patterns in testing involving seven users, with F1 scores ranging from 93.1% to 100%.
The researchers also monitored pseudo-terminal activity over SSH and achieved a 100% F1 score in their test scenario. Passwords entered into terminals with input echo disabled were not observable.
On Windows, the researchers found that monitoring the root of the C: drive could expose file paths associated with another user’s profile, even when the monitoring user did not have permission to access those directories.
Browser activity was another concern. File-system patterns created by browser storage could help identify websites visited by a user. In the study, Firefox activity from 975 of the top 1,000 tested websites could be identified, achieving a 97.8% F1 score in the researchers’ test. Edge produced fewer site-specific patterns and achieved a 48.5% F1 score.
macOS Reveals Less, But Still Exposes Activity
macOS provided stronger separation between users because FSEvents does not freely expose private directories belonging to other users.
However, researchers were still able to identify patterns associated with activities such as application launches, system setting changes, printing, network activity, external storage, Bluetooth devices, and virtual machines.
The average notification latency on macOS was around 11.48 milliseconds, making it slower than the other platforms tested. Despite this, researchers said the information could still be useful for behavioral monitoring.
Importantly, this technique is not a remote attack that can compromise a computer over the internet. Malicious software must already be running on the machine as a local, unprivileged user.
That makes the technique more relevant to post-compromise surveillance, where malware already present on a system attempts to gather additional information about the victim.
Researchers Recommend Stronger Protection
The researchers reported their findings to Linux, Microsoft, Apple, and KDE in October 2025.
Linux introduced a partial mitigation for certain device files in early 2026. Microsoft classified the behavior as being by design and provides the EnforceDirectoryChangeNotificationPermissionCheck policy to restrict certain unauthorized path disclosures. The researchers noted that this setting is disabled by default.
The researchers recommend stronger permission checks that clearly separate files a user owns, files they can read, and protected files belonging to others. They also recommend tighter controls on applications that attempt to monitor large sections of the file system.
Organizations can reduce the risk by keeping systems updated, limiting untrusted software, using application sandboxing, separating service accounts, and applying stricter notification permissions where available.
The research highlights an important security lesson: attackers do not always need to read sensitive data to learn something about a user. File paths, timing information, and system notifications can become valuable sources of intelligence when analyzed together.