Skip to content

Security1 publisher2 min readPublished

Graz researchers read other users' browsing and keystroke timing through OS file-change alerts

Graz University of Technology researchers used file-change alerts to catch 95.7% of another Windows user's Firefox site visits from an unprivileged account. On shared hosts and on servers that run services under their own accounts, separation between users is weaker than the account model suggests.

The Watch · Security desk

Illustration accompanying Graz researchers read other users' browsing and keystroke timing through OS file-change alerts

What happened

  • On Linux, watching the keyboard's device file gave key-press timing that caught nearly every keystroke from seven typists on a test laptop.
  • Over SSH, a process on the server caught each of the 402 keystrokes a remote user typed.
  • A watch on the root of the C: drive returned full paths of file changes inside other users' home folders that the watching account could not open.
  • Microsoft's update KB5058189 added a mitigating registry policy, but it ships disabled, and every Windows attack in the paper works on an out-of-the-box system.
  • Sébastien Huneault separately reported similar behavior to Microsoft in April 2025 (CVE-2025-27738, CVE-2025-21197); the Graz team says it learned of this after submitting its paper.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any tenant on a shared host, or a service account an intruder has taken over, can profile other users' web and terminal activity without escalating privileges.
  • decision Windows operators running multi-user hosts have to switch the permission-check policy on themselves, because the vendor treats the current default as correct.
  • constraint A watcher that uses at most 0.21 percent of CPU is unlikely to stand out in load monitoring, so resource alarms will not reliably catch one.

The attacker has to be on the machine already. Every attack in the paper runs code under a second, unprivileged account on the victim's host [6]. The paper names compromised Linux services as one route in. Systemd often runs services under their own users [6]. That account needs no further privileges. Linux's inotify, Windows' ReadDirectoryChangesW and macOS's FSEvents each let an ordinary account watch any directory it can read [7].

The method starts with mapping. The team did everyday tasks while recording every file event on the system, then kept the files whose events tracked each task [13]. The resulting templates covered terminal commands, keyboard and mouse input, browsing, printing, virtual machines and Docker containers, Bluetooth, network and VPN changes, and USB devices [13].

The Windows browsing result comes from folder names. Browsers keep per-site data in folders named after the site's address. Firefox writes one when a site uses local storage, IndexedDB or its cache, while Edge and other Chromium browsers write one only for IndexedDB [20]. On Windows 11 24H2 the team loaded the top 1,000 sites, and 975 responded [16]. Firefox's 95.7 percent works out to about 933 of those sites and Edge's 32 percent to about 312, with zero false matches in either browser [2][3][1][2]. The paper attributes Edge's lower rate to the smaller share of sites that use IndexedDB [3].

The drive-wide watch picked up more. Prefetch files carry the name of each program launched, ssh included [15]. Zoom's database files changed in distinct ways as a user entered a waiting room, joined a meeting and left [15]. A Windows Defender scan raised one event per file it checked, exposing paths to other users' documents, videos and browser data [14]. Defender appeared to skip unchanged files on later scans, so the paper ties that leak to the first scan [14].

Microsoft told the team the behavior is by design and "only reveals file names and paths within another user's profile directory." [9] The browsing history above was rebuilt from those names and paths alone, and the authors argue Microsoft should reconsider [19].

On Linux the leak is timing. An account that can read a folder gets alerts for every file in it, including files it is barred from opening [18]. The keyboard's device file is one of them. The watcher learns when a key went down and came up, not which key [4]. Earlier studies have shown that rhythm can help reconstruct typed text [17]. In the SSH test, input typed into hidden password prompts such as sudo's did not register [5].

What to watch

  • Whether Microsoft ships EnforceDirectoryChangeNotificationPermissionCheck enabled by default or revisits its by-design ruling.
  • Whether Linux restricts inotify events on files a watcher cannot open, starting with input device files.
  • Any report of file-notification templating used outside research, particularly through compromised service accounts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories