In an account published September 28, 2026, researchers at Graz University of Technology (TU Graz) reported that file-notification systems on Linux, Android, Windows and macOS can expose file events and, in some cases, filenames—clues that can reveal user activity without revealing file contents.
What file notifications can reveal
Operating systems use file notifications to tell applications when files change. A side channel emerges when someone can watch those event signals and use their timing, filenames or patterns to infer what another user is doing. In the TU Graz demonstrations, the exposed information was activity-related metadata, not the contents of the files.
How the examples differ across four systems
The researchers examined a different notification mechanism on each operating system. Their examples range from file activity inside an otherwise unreadable directory to filenames that can point to websites visited in Firefox.
| Operating system | Notification mechanism | Reported example | Exposed information and stated limit |
| Linux | inotify | Watching a readable parent directory such as /dev/input can produce events for files inside it that the watcher cannot read directly. | The /dev/input example reveals keypress timing, not which key was pressed. |
| Android | FileObserver, a Java wrapper around inotify | An unprivileged app can observe activity and filenames in another app’s private folder despite FUSE’s per-app storage isolation; the researchers used WhatsApp media folders as an example. | Events can distinguish sent from received media and reveal deletions; the notifications do not expose file contents. |
| Windows | ReadDirectoryChangesW | Watching C:\ can expose file events and paths across users, including Firefox website-storage folder names. | Those names can reveal website visits; the notifications do not expose file contents. |
| macOS | File System Events (FSEvents) | The researchers found that user, application and system activity could still be tracked. | They reported less exposure than on the other three systems and no private-directory leaks. |
The access conditions behind the demonstrations
The researchers say the demonstrations require a local attacker able to cross user boundaries—for example, through a compromised user account or system service—or a package compromised in a supply-chain attack. The finding describes what that attacker could infer from notification events under the demonstrated conditions.
What the researchers say about mitigations
Linux partially mitigated access and modify notifications on special files in December 2025. The change addresses some severe examples, but the researchers say it does not fully mitigate the wider issue.
For Windows, the researchers say Microsoft’s EnforceDirectoryChangeNotificationPermissionCheck registry policy mitigates the reported behavior. The policy is disabled by default. The researchers report no mitigation for Android or macOS.
The paper’s ACM CCS schedule
The paper was accepted to the ACM Conference on Computer and Communications Security (CCS), scheduled for November 15–19, 2026, in The Hague.