“File Notification Attack” Exposes User Actions Across Linux, Windows & macOS

A newly disclosed side-channel method, titled “File Notification Attacks,” can silently monitor activity on Linux, Windows, and macOS without needing admin or root rights. Developed by researchers at Graz University of Technology, it repurposes built-in file-notification services—such as inotify, ReadDirectoryChangesW, and FSEvents—to leak sensitive information about what users are doing just by watching which files change, when.

What the Attack Tracks

The attack works by recording timing and file-path notifications while users perform actions. Templates created during this “templating phase” make it possible to later match observed file changes to specific behaviors—everything from keyboard and mouse input, terminal commands, visiting websites, virtual machine or container activity, printing, Bluetooth or VPN toggles, to connecting USB devices.

Performance tests showed that the attack can pick up file changes with latency ranging from 0.2 ms to about 11.5 ms, depending on platform, while increasing CPU use by no more than 0.21%.

Platform-Specific Risks

On Linux, even unreadable directories—like device files in /dev—are still observable via notifications from parent folders. This makes it possible for a non-privileged user account to detect when files in those directories are accessed, enabling attack paths like keystroke-timing detection with high accuracy.

Windows proved especially vulnerable: if a malicious user monitors the root “C:” drive, paths inside another user’s profile become visible, even if direct read access is denied. Attackers could thus track visited websites—such as those stored by Firefox—with nearly perfect precision among a top-1000 sites list.

macOS leaked less detail due to restrictions on accessing private folders across users. Still, shared system areas revealed when apps launched, settings were adjusted, printing occurred, connections changed, external storage was used, or virtual machines were running. Latency here was highest—around 11.5 ms—but still sufficient for detailed behavioral monitoring.

This kind of attack doesn’t require app exploits or memory hijacking. Instead, it abuses expected behavior of OS-level file change notifications to reconstruct user workflows. That means even after a system’s compromised at low privilege, these side-channels let adversaries spy without needing further permission.

Mitigation: What’s Being Done & What’s Suggested

The research team disclosed their findings to the major OS developers—Microsoft, Apple, Linux maintainers, KDE—in October 2025. Linux has already partially mitigated attacks involving device files, though bypasses for unreadable directories remain open.

Microsoft considers much of the behavior “by design”; a policy named EnforceDirectoryChangeNotificationPermissionCheckcould limit exposure, but it’s turned off by default.

Best practices to reduce risk include applying permission checks that differentiate between file owners vs. protected content, enforcing stricter harvesting rules (especially for whole-drive notifications), sandboxing untrusted programs, segmenting service accounts, and keeping up with OS updates. Treating metadata—like filenames, timing of access, and notification attributes—as critical telemetry is also essential.

Because file-notification systems were never designed to conceal all changes, the attack falls in the gap between what’s visible in the system and what’s supposed to be private—even when files themselves aren’t readable.

Why it matters:Most users trust built-in file-watching APIs to signal only harmless changes—like a file saving or backup completing. This research shows that what appears benign can be turned into a fine-grained lens on user behavior. As the boundaries of privacy get sharper, this attack forces a rethink about what metadata we allow apps and processes to observe—and whether default settings should favor tighter restrictions.