CVE-2025-27738
CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89th percentile).
Vulnerabilities & Exploits
Researchers at Graz University of Technology showed that file-notification APIs in Windows, Linux, macOS, and Android can let a low-privilege account infer what another account is doing. Their proof of concept covered browser visits, app launches, file events, and keystroke timing across the same machine.
The trick is to watch the operating system’s normal “this file changed” signals instead of the files themselves. Browsers and apps leave distinctive event patterns, so a separate user can rebuild a timeline of activity without reading the victim’s data or touching the network.
For shared desktops, VDI, remote sessions, or service-user hosts, the privacy boundary is weaker than separate logins suggest. The exposure is local and persistent: if two accounts share the machine, one may still learn when the other browses, types, or opens apps even after standard file permissions do their job.
1 source · 6h ago
CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89th percentile).
CVSS 6.5 MEDIUM: improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a… EPSS 3% (88th percentile).
EPSS 0.2% (10th percentile).
Help Net Security
Other users can watch your browsing and time your keystrokes through OS file notifications - Help Net Security
File notification attacks in Windows, Linux, and macOS let other accounts on a shared PC track browsing, keystroke timing, and app launches.
originalPart of the PlainSec briefing for 2026-09-28
Every edition of this story: File Notifications Leak Activity Across User Accounts