Researchers at Graz University of Technology have shown that operating-system file notification features can act as side channels for user and application activity. The mechanisms are designed to alert software when files change, but event timing and path information can reveal behavior even when an attacker cannot read file contents.
The exposure varies by operating system
The demonstrations included keystroke timing and website fingerprinting on Linux, cross-user path visibility on Windows and WhatsApp media events on Android. Most scenarios require an attacker to run code locally, often under another account; the Android test used an application requesting no permissions. The work does not show remote compromise by itself, and the researchers said they were unaware of exploitation in the wild.
Linux has partially hardened device-file events associated with one of the more serious paths. Microsoft told the researchers that the Windows behavior is by design and emphasized that it exposes paths rather than file contents. The project lists no general fix for several other scenarios.
Local isolation still matters
Administrators should limit untrusted local code, separate sensitive workloads and monitor unusual use of file-watching APIs where telemetry is available. Application developers should minimize sensitive information in file names and temporary paths. SectechMedia follows endpoint risks in its cybersecurity coverage.

Leave a Reply