Researchers Identified Major File Notification Flaws
Vulnerabilities across Windows, Linux, macOS, and Android allow unauthorized users to track activity.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust that your computer operating system keeps your background activity private from other users?
Security researchers at Graz University of Technology uncovered flaws in file notification subsystems that let unauthorized users track system activity. The vulnerabilities affect Linux, Android, macOS, and Windows operating systems.
Why it matters
These systems currently fail to restrict access to file event data, allowing attackers to monitor modifications and infer user behavior. This flaw enables malicious actors to perform website fingerprinting and keystroke monitoring.
Researchers demonstrated the risk with 100 percent accuracy in remote SSH keystroke tracking and 97.8 percent accuracy in real-time website tracking on Windows. Website fingerprinting accuracy reached 87.9 percent across affected platforms.
The players
Graz University of Technology
This Austrian public university is a leading institution for technical research and education.
ACM CCS
This is a premier international forum for researchers and practitioners to discuss security and privacy.
The details
Attackers can monitor file modification notifications to conduct UI redress attacks and inter-keystroke-timing analysis. While Linux kernel CVE-2025-68788 received a partial patch, Microsoft continues to classify the Windows behavior as an undocumented design feature.
Timeline
The Windows ReadDirectoryChangesW subsystem was originally introduced in 2000.
Researchers disclosed their findings to security teams between August and October 2025.
A patch for Linux kernel vulnerability CVE-2025-68788 was released in December 2025.
The full research paper is scheduled to appear at ACM CCS 2026 in November 2026.
The Tech Race
These findings signal a major paradigm shift in how operating systems manage inter-process communication and file access. The research highlights the tension between legacy design features, such as those dating back to 2000, and the modern requirement for robust storage isolation.
Users currently have no direct way to mitigate these vulnerabilities beyond staying updated on security patches. Until manufacturers address these architectural flaws, individuals should remain cautious about running untrusted processes that could monitor file activity.
The takeaway
These findings emphasize that even long-standing system features can become significant privacy risks as attack methods evolve. Users must be aware that file activity monitoring can inadvertently expose sensitive information like keystrokes and browsing habits.
What happens next
The comprehensive research findings are slated for official presentation at the ACM CCS 2026 conference in The Hague in November 2026.
Further reading
For additional context on systemic risks, explore the Cybersecurity section.
More information
View the full details on the research paper summary portal.
Live Poll
Do you trust that your computer operating system keeps your background activity private from other users?







