Skip to finding
§
Medium
Research — privilege
Confirmed
CVE-2025-68788

File notifications let ordinary local code watch private activity it cannot read.

An unprivileged local user—or a permissionless Android app on affected shared storage—can observe events across another user’s or application’s boundary.

Affects

Linux inotify, Android FileObserver, Windows ReadDirectoryChangesW, and macOS FSEvents, the filesystem-change notification APIs built into their respective operating systems.

What it enables

Cross-user activity surveillance from filesystem-event metadata without permission to read the underlying files

Attacker runs an ordinary local process or permissionless Android app→↓The process registers a filesystem-event watcher on a readable parent, shared-media directory, or Windows drive root→↓The notification subsystem reports events for files the attacker cannot directly read or enumerate→↓Filenames and timing reveal keystroke intervals, visited websites, WhatsApp media send/receive/delete events, or the appearance of an authentication prompt
Why this matters

Runnable artifacts show one metadata side channel crossing account and application boundaries on Linux, Android, and Windows; the available Linux mitigation removes only part of the class.

Detail, proof-of-concept code and 4 sources
Required access

Execution as an unprivileged local user, or as a permissionless Android app on affected shared-storage paths

Affected versions

Linux inotify implementations where readable parents expose events for protected children; the most severe /dev path affects kernels before the listed stable mitigations, Windows systems where EnforceDirectoryChangeNotificationPermissionCheck is disabled, which the researchers report is the default, Android versions whose scoped-storage configuration still permits FileObserver registration on WhatsApp shared-media directories, macOS FSEvents, with lower-impact activity leakage and no demonstrated private-directory bypass

Proof of concept

Public exploit code →

The attacker watches a readable parent, shared-media directory, or Windows drive root. Event timing and, on Windows and Android, protected filenames can expose typing cadence, visited sites, WhatsApp media activity, or the appearance of an authentication prompt.

The researchers report no known exploitation in the wild. Linux now suppresses two event types on special files, but the broader notification boundary remains.

Evidence
The researchers published demonstrations and runnable artifacts for Linux, Android, and WindowsThe Linux mitigation only suppresses access and modify events on special files; the broader class remainsThe researchers report no known exploitation in the wild
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026