CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Other users can watch your browsing and time your keystrokes through OS file notifications

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8706

As cited

Copy frozen at (site build).

vulnerabilities

Other users can watch your browsing and time your keystrokes through OS file notifications

Researchers at Graz University of Technology discovered that file-notification systems in Windows, Linux, and macOS can be abused by unprivileged accounts to monitor activity in other user sessions. On Windows, the technique detected over 95 percent of website visits to popular sites in Firefox, while on Linux, keystroke timing was exposed in both local and SSH sessions. These notification mechanisms, designed for legitimate application use, create a cross-account information disclosure vulnerability.

Why it matters: Any user on a shared Windows, Linux, or macOS system can monitor other users' browsing and keystroke patterns without elevated privileges, affecting multi-user environments, shared servers, and SSH access; practitioners should review user isolation and consider restricting file-notification visibility where sensitive work occurs.

VendorsMicrosoftApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary