A novel side-channel attack capable of tracking user activities across Linux, Windows, and macOS has been uncovered, leveraging file-notification services such as inotify, ReadDirectoryChangesW, and FSEvents. This technique uses these services, which traditionally alert applications to file changes, as monitoring tools without the need for elevated privileges.
Research Origins and Methodology
This discovery stems from a study conducted by researchers at Graz University of Technology, titled “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS.” The researchers developed a templating process to record filesystem events linked with various user actions.
These templates can discern a wide range of activities, including terminal commands, input from keyboard and mouse, website visits, web-server activity, and more. The attack does not exploit memory corruption but instead observes the timing and paths of legitimate operating-system notifications.
Implications for Different Operating Systems
On Linux, the attack exploits inotify’s ability to report file-access events, enabling the detection of keystroke timing with high accuracy. It can also efficiently monitor SSH pseudo-terminal activity. On Windows, the attack allows an unprivileged user to access file paths within another user’s profile, revealing visited domains through browser storage paths.
MacOS, while slightly more resilient due to its restrictions on monitoring private directories, still exposes application launches and network activity. The average latency on macOS is slower compared to the other systems, yet remains effective for behavioral analysis.
Security Implications and Recommendations
The attack represents a significant threat in terms of post-compromise surveillance, allowing malware to infer user behaviors without direct file access. Although researchers disclosed these findings to major operating system vendors in October 2025, responses have varied. Linux has implemented partial mitigations, whereas Microsoft regards the behavior as intended.
The study suggests that filenames, access timing, and notification metadata should be considered sensitive. Enhanced permission checks, sandboxing applications, and updating operating systems are recommended to mitigate exposure. The potential for false interpretations exists when different activities create similar filesystem patterns.
In conclusion, while the attack does not allow remote compromise, it underscores the need for improved security in file-notification systems to protect user privacy and system integrity.
