E-Ink News Daily

← Back to list

File Notification Attacks: Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS

A paper accepted at CCS 2026 reveals critical side-channel vulnerabilities in file-notification systems across Linux, Android, Windows, and macOS, where attackers with only read permissions can reconstruct user behavior by monitoring file-change notifications. Three platform-specific severe issues were found: Linux's inotify leaks events for files inside readable directories regardless of individual file permissions, Android's FileObserver bypasses FUSE sandboxes to watch other apps' private folders, and Windows' ReadDirectoryChangesW exposes full paths and cross-user activity even from the root directory.

Background

This research was presented at CCS 2026 in The Hague, Netherlands, exposing fundamental design flaws in core OS file-notification subsystems that have existed since their introduction (inotify since 2005, FileObserver since 2008, ReadDirectoryChangesW since Windows 2000). The findings earned Microsoft a nomination for the lamest vendor response at the Pwnies Award 2026.

Source
Lobsters
Published
Sep 25, 2026 at 10:50 AM
Score
8.0 / 10