Windows, Linux, Android File Notification Systems Leak User Activity

Windows, Linux, Android File Notification Systems Leak User Activity
Researchers at Graz University of Technology showed that file-change notifications in Linux, Android, Windows, and macOS can leak user activity such as typing rhythms, website visits, and app interactions. They also found serious impacts on Linux, Android, and Windows, including keystroke inference, WhatsApp file monitoring, and full path disclosure, with a Linux fix tracked as CVE-2025-68788. #GrazUniversityofTechnology #CVE-2025-68788 #WhatsApp #Firefox #KDEPlasma6 #Microsoft

Keypoints

  • File-change notifications can be abused to observe user activity across Linux, Android, Windows, and macOS.
  • Attackers can infer keystroke timing, websites visited, and application behavior without reading file contents.
  • Linux folder-watching can reveal keystrokes and enable a fake password prompt attack on KDE Plasma 6.
  • Android apps without permissions can monitor private storage, exposing WhatsApp media transfers and deletions.
  • Windows can leak full file paths, while macOS leaks less but still exposes app launches and settings changes.

Read More: https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/