Decades-old flaws in Android, Linux, macOS and Windows allow spying on file activity
A team of researchers at Graz University of Technology (Austria) has found that the mechanisms operating systems use to report file changes leak more information than they should. They have existed for decades —ReadDirectoryChangesW on Windows since 2000, inotify on Linux since 2005, FSEvents on macOS since 2007 and FileObserver on Android since 2008— and reveal when a file is opened, modified or deleted without needing to read its contents.
By watching those notifications, an app with no special permissions can infer a lot: the researchers measured keystroke timing with 93% to 100% accuracy, identified which of the 100 most popular websites was being visited with 87.9% accuracy and even tracked other users’ file activity. Responses have been mixed: Microsoft considers the behaviour to be “by design”, Linux applied a partial fix in December 2025 and Android has taken no action. The study will be presented in November at the ACM CCS 2026 conference.
Tip from Soporte Informático 360
These attacks require a malicious app to already be on the computer or phone, so the best defence is still to install software only from official sources, keep the system up to date and regularly review installed programs.
Source: The Register. Summary prepared by our team for informational purposes.
IT maintenance for businesses
Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.