New File Notification Attack Exploits OS Services for Cross-Platform Surveillance
Researchers have detailed a novel cross-platform attack that abuses operating system file-notification services on Linux, Windows, and macOS to covertly monitor user activity without requiring elevated privileges.

A sophisticated new side-channel attack, dubbed the "New File Notification Attack," has been detailed by researchers from Graz University of Technology. This technique ingeniously leverages the legitimate file-notification services built into Linux, Windows, and macOS—namely inotify, ReadDirectoryChangesW, and FSEvents, respectively—to transform them into a powerful surveillance mechanism. Unlike traditional exploits that target memory corruption, this attack operates by observing the timing and file paths of standard system notifications, correlating these events with recognizable user behaviors to infer activity.
The research, published in a paper titled "File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS," outlines a semi-automated templating process. This method involves recording filesystem events while specific actions are performed, creating templates that can later identify a wide range of user activities. These identified behaviors include terminal commands, keyboard and mouse input, website visits, web-server interactions, printing jobs, virtual machine and container activity, Bluetooth and VPN changes, and even USB device interactions. The attack imposes minimal overhead, with researchers measuring CPU usage below 0.21% and achieving event resolution as low as 0.2 milliseconds.
On Linux, the inotify service provides particularly fine-grained signals. By monitoring parent directories, an unprivileged account can receive notifications about file access events even for files it cannot directly read, including sensitive entries under /dev. This capability was demonstrated to enable local keystroke-timing detection with high accuracy (93.1% to 100% F1 scores for seven users). Furthermore, monitoring pseudo-terminal activity over SSH achieved a perfect 100% F1 score, though password fields that suppress terminal echo were not observable.
The attack also demonstrated a practical UI-redress vulnerability against KDE Plasma 6 on Wayland. By observing notifications related to the execution of PolicyKit’s pkexec component, malicious code could time the appearance of a counterfeit window to overlay the legitimate prompt, potentially tricking users into granting unintended permissions. Additionally, Firefox font-access patterns were analyzed to enable open-world fingerprinting of the top 100 websites with an impressive 87.9% F1 score.
Windows exhibited the most direct privacy leak. An unprivileged user monitoring the root of the C: drive could receive file paths located within another user's profile, even without explicit read permissions for those directories. This allowed for the monitoring of browser storage paths, revealing visited domains. For Firefox, this technique achieved a 97.8% F1 score for website monitoring across 975 responsive sites within a top-1,000 list. Microsoft, however, classified this behavior as "by design," although a related policy, EnforceDirectoryChangeNotificationPermissionCheck, can restrict unauthorized path disclosure but is disabled by default.
On macOS, the FSEvents service revealed less information due to restrictions on monitoring private directories across users. Nevertheless, shared system files still provided insights into application launches, system setting changes, printing activities, network cable status, external storage connections, Bluetooth device modifications, and the state of VMware virtual machines. While its average latency of 11.48 milliseconds was the slowest among the three platforms, it remains sufficiently useful for behavioral monitoring.
Crucially, this attack requires malicious code to be running as an unprivileged local user on the target system; it is not a standalone remote compromise method. Its primary danger lies in its stealthy nature as a post-compromise surveillance tool. Malware could potentially infer sensitive user behaviors without needing to read protected content, inject code into applications, or employ complex hardware-specific cache attacks. Researchers disclosed their findings to Linux, Microsoft, and Apple in October 2025. While Linux deployed a partial mitigation for device files in early 2026, the broader bypass for unreadable files persists. Microsoft's stance and the default disabled status of a relevant policy highlight the ongoing challenges in addressing such side-channel vulnerabilities.
The researchers recommend implementing stricter permission checks that differentiate between owned, readable, and protected files, alongside tighter controls on whole-drive monitoring. They emphasize that filenames, access timing, and notification metadata should be treated as sensitive telemetry. Mitigation strategies include sandboxing untrusted applications, segregating service accounts, applying timely OS updates, and enabling stricter notification-permission controls while vendors redesign these APIs to enhance security.