File Notification APIs on Linux, Android, and Windows Leak User Activity, Researchers Find
Researchers from Graz University of Technology have disclosed a side-channel attack that exploits file change notification systems on Linux, Android, Windows, and macOS to infer user activity without elevated privileges. Unprivileged local processes and Android apps requiring no special permissions can monitor file notification events to estimate keystroke timing, browsing destinations, and WhatsApp media interactions without accessing file contents. On Linux, the technique also enables UI spoofing, where a fake KDE Plasma authentication screen overlays the legitimate one to steal credentials entered by the victim. The severity is rated high because the attack requires only local code execution, and a proof-of-concept has been published, though active exploitation in the wild has not been confirmed. Partial mitigations exist on Linux, while Windows mitigations are disabled by default.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in