Vulnerabilities · 5h ago

File Notifications Leak Activity Across User Accounts

Researchers at Graz University of Technology showed that file-notification APIs in Windows, Linux, macOS, and Android can let a low-privilege account infer what another account is doing. Their proof of concept covered browser visits, app launches, file events, and keystroke timing across the same machine.

The trick is to watch the operating system’s normal “this file changed” signals instead of the files themselves. Browsers and apps leave distinctive event patterns, so a separate user can rebuild a timeline of activity without reading the victim’s data or touching the network.

For shared desktops, VDI, remote sessions, or service-user hosts, the privacy boundary is weaker than separate logins suggest. The exposure is local and persistent: if two accounts share the machine, one may still learn when the other browses, types, or opens apps even after standard file permissions do their job.

CVE-2025-27738

NVD KEV

CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89th percentile).

CVE-2025-21197

NVD KEV

CVSS 6.5 MEDIUM: improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a… EPSS 3% (88th percentile).

CVE-2025-68788

NVD KEV

EPSS 0.2% (10th percentile).

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-28

Editions

Related stories