File Notification APIs Enable Cross-User Keystroke Timing and Site Fingerprinting on Windows Linux Android
File notification systems across four major operating systems leak sufficient metadata for unprivileged side-channel attacks on user activity. Partial Linux hardening leaves most platforms exposed while vendors classify the behavior as non-vulnerable. The pattern reveals systemic underestimation of metadata exposure in standard OS APIs.
Operational impact is highest on shared multi-user systems and Android devices where sandboxing assumptions are undermined. The same notification streams that support legitimate file managers also enable real-time reconstruction of hidden password entry application launches and browser activity across accounts. Future mitigations will require changes to event granularity or mandatory access controls on notification channels rather than relying on per-file permissions that are already bypassed at the folder level.
Microsoft: No changes to root-drive notification paths shipped in Windows 11 by end of 2026 despite 97.8% fingerprinting results
Sources (2)
- [1]SecurityWeek Coverage(https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/)
- [2]CVE-2025-68788 Kernel Patch(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68788)