A service that every mainstream operating system ships to tell applications when a file has changed has turned out to be a listening device. Researchers in Austria spent the past year converting those change notifications into a side channel, and the Mac answers some of their questions.
The work comes from Graz University of Technology. Doctoral student Sudheendra Raghav Neela led it with Daniel Gruss and five colleagues, and the resulting paper, File Notification Attacks, is scheduled for ACM CCS 2026 in The Hague this November. A plain-language summary sits at inoti.fyi.
What the Mac gives away
Apple’s implementation is FSEvents, which has reported file activity since 2007. It proved the tightest of the four systems examined: the team found no way to read private directories through it. The exposure is narrower and stranger. Watching property list files reveals when audio inputs and outputs switch, when power settings change, when a Bluetooth device or printer appears, and when a network cable triggers a DNS change. Volume mounts and ejections show up, and so do application installs and removals.
Timing is the whole trick
None of those events carries file contents. Their timing carries plenty. The group built keystroke-timing attacks that recover typed text, fingerprinting that identifies which sites a browser visits, and redress tricks that can steal credentials; on a Linux desktop they spoofed an authentication prompt.
The authors want kernels to check permissions before any process can subscribe to file monitoring, and on Windows and macOS they propose a dedicated access-control layer for it. The Linux half of the flaw, tracked as CVE-2025-68788, was partly addressed in December. Apple has not commented publicly.