File notifications let ordinary local code watch private activity it cannot read.
An unprivileged local user—or a permissionless Android app on affected shared storage—can observe events across another user’s or application’s boundary.
Linux inotify, Android FileObserver, Windows ReadDirectoryChangesW, and macOS FSEvents, the filesystem-change notification APIs built into their respective operating systems.
Cross-user activity surveillance from filesystem-event metadata without permission to read the underlying files
Runnable artifacts show one metadata side channel crossing account and application boundaries on Linux, Android, and Windows; the available Linux mitigation removes only part of the class.
Detail, proof-of-concept code and 4 sources
The attacker watches a readable parent, shared-media directory, or Windows drive root. Event timing and, on Windows and Android, protected filenames can expose typing cadence, visited sites, WhatsApp media activity, or the appearance of an authentication prompt.
The researchers report no known exploitation in the wild. Linux now suppresses two event types on special files, but the broader notification boundary remains.
- access:local:unprivileged
- code running as an unprivileged local user
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No
Definite answers use the Linux/Ubuntu patch path; the finding spans multiple operating systems whose deployment behavior differs.