Researchers at Graz University of Technology have demonstrated that the file-notification systems built into Windows, Linux, and macOS can be abused to spy on activity occurring in other user accounts on the same machine. On Windows, a standard unprivileged account was able to detect 95.7 percent of another user's visits to popular websites in Firefox. Similar techniques were shown to work on Linux and macOS, though the source does not give specific detection rates for those platforms.

The attack works by monitoring file-notification events, which the operating system generates whenever files are created, modified, or deleted. These events are normally used by applications to track changes, but the researchers found that they leak enough timing and naming information to infer what websites a user is visiting and even to time individual keystrokes. Because the attack requires no special privileges—only a standard user account—it breaks the isolation that operating systems are supposed to provide between users.

The findings highlight a previously underappreciated side channel in core OS mechanisms. The source does not mention any vendor patches or mitigations, and the researchers' work appears to be a proof-of-concept rather than a fix. As file notifications are deeply embedded in how these systems operate, addressing the issue may require careful redesigns or strict permission controls, but no concrete solution is discussed in the source.