What a Program Can Learn About You Without Reading a Single File

Open a folder and the listing fills itself in. Drop a file into it from somewhere else and the window updates before you can blink. Your computer is not checking that folder over and over to notice; it is being told. Underneath almost every file manager, desktop search index, cloud sync client and code editor sits the same quiet convenience, a subsystem that announces file events to any program that asks to hear them. Linux has had one since 2005, Windows since Windows 2000, macOS since 2007 and Android since 2008.
A team of seven at the Institute of Information Security at Graz University of Technology asked who else is listening. Their answer, published on September 28, 2026 alongside a paper accepted at this year's ACM Conference on Computer and Communications Security, is that a program running on the same machine as you, under a different account and with no special privileges, can subscribe to those announcements and rebuild a surprising amount of what you are doing. It never reads a file. It learns only that files exist, that they changed, and when.
The weakness is one step of indirection. A program that cannot read a file is refused a watch on that file, exactly as you would hope. Ask instead to watch the folder the file sits in, and the request succeeds, and the notifications that come back cover everything inside it, including the file that was off limits. Permission to look at a directory, a far weaker thing to hold, becomes a live feed of activity on files that permission was meant to protect.
A keyboard, a password box, a chat folder and a browser
On Linux, the first demonstration is a keyboard. Sudheendra Raghav Neela, the paper's first author; Daniel Gruss, who leads the group; and their colleagues report that a watcher is notified every time the machine's input device registers a press. Which key was pressed does not leak, only that a key was pressed, and exactly when. That sounds thin until you know that the gaps between keystrokes have been mined for information for more than twenty years, because typists are quicker on some letter pairs than others. The same signal turns up between two people logged in to one server.

A second case on Linux is blunter. A watch of the same kind tells a program the moment the system is about to put a password prompt on screen, which is time enough to draw a convincing fake over the real one and collect whatever is typed into it. That worked under Wayland, the display system built to stop one program from spying on another's input. KDE's security team told the researchers that its rule against windows stealing focus was never meant as a security measure.
On Android the same idea reaches into another app's private storage. Each app's folder is hidden from every other app, and an app that asks for a listing of WhatsApp's media folder is handed an empty one. The hiding does not extend to notifications. An app holding no permissions at all was told about every file arriving, moving or being deleted in that folder, with the name attached, and the names give away the kind of item and whether it was sent or received. What falls out is a timeline of somebody's messaging.
Windows is the worst of the four. A watch placed on the root of the system drive is not refused, and it reports the full path of every file touched anywhere on the machine, by anyone, whatever the permissions on it. Browsers are loud in that feed, because Firefox makes a separate directory for each site that uses local storage, and the directory carries the site's name. From another account on the same computer, the team could tell which of the thousand most visited websites another user was on, as it happened, with an F1 score of 97.8%, a measure that counts misses and false alarms together. Microsoft, the authors write, told them during disclosure that it regards the behavior as an undocumented feature.
macOS is the exception, and that is the more interesting result. Its notification service reports only files the watcher was entitled to read anyway, so the team found no private information exposed there, just broad patterns of user, application and system activity. None of this works from the internet, either. The attacks need a program already running on the machine under another account, which in practice means a compromised service, or code that arrived inside a software package somebody trusted. The researchers say they know of no case where any of it has been used.
Four vendors, four different answers
The Linux kernel took a patch, assigned CVE-2025-68788, that stops notifications from being generated for the special device files the keyboard case depends on. The authors call that a partial mitigation, and it is: the rest of the filesystem behaves as it did before. It reached the stable kernels released in January 2026, and the CVE record names the versions that carry it.
Microsoft's side has a fix that ships turned off. Its own support note, prompted by bugs a separate researcher, Sébastien Huneault, reported in April 2025, describes a policy that makes Windows check whether you are entitled to a file's path before telling you it changed. The note is explicit that the policy is disabled by default, so that it does not break software expecting the old behavior. Administrators who want it will find it named there. For Android and macOS there is nothing to switch on.
What to do while the rest of it stands open
The paper itself, which Graz University of Technology's own announcement titles "File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS," is accepted at the ACM security conference and due to be presented in The Hague in November 2026.
So the practical part is short. Update, because a kernel fix only protects machines that take it, and on Windows the protection exists and is switched off. The permission systems everyone relies on were built to guard what is inside a file, and a notification is not inside the file.
