Monday, September 28, 2026

 

File-notification systems leave Windows, Linux, Android and macOS vulnerable


A research team at Graz University of Technology has demonstrated that the file notification systems of various operating systems can be exploited to spy on users' activities and forge password prompts.




Graz University of Technology

The File Notification Systems of popular operating systems allow spying

image: 

The File Notification Systems of popular operating systems allow spying

view more 

Credit: Brinda Neela; CC BY 4.0; https://inoti.fyi/






Researchers at the Institute of Information Security at Graz University of Technology (TU Graz) have uncovered security risks in the file notification systems of the widely used operating systems Windows, Linux, Android and macOS. Through so-called side-channel attacks, system-wide changes to files, keystrokes and visited websites can be tracked, and password prompt windows can be spoofed to intercept password entries. The researchers summarised their findings in the paper “File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS, which they have published on a dedicated website: https://inoti.fyi

A workaround via readable folders

File notification systems monitor whether files are created, deleted, opened, closed or modified, and automatically deliver system notifications so that applications or the system can react to the change. The research team discovered that apps or other users on the same system can monitor these notifications, even without administrator rights. This makes it possible to track what other users on the system are doing. Read access to specific folders is all that is required to read all files stored in a folder, as well as the subfolders and their contents – even if they do not actually permit read access. One thing that applies to all systems: file contents cannot be read; only file names and changes can be detected. However, this is sufficient to monitor user, system and application behaviour.

Browsing history can be tracked

The research team uses case studies to illustrate what such attacks could actually look like. To bypass the read-access restrictions on folders and files in Windows, the researchers simply tapped into the file notification system of the parent directory that was not read-protected. Using notifications of the main directory C:\, the researchers discovered that it was possible to track all file system events in all subfolders, including filenames. As browsers such as Firefox create a separate folder for every visited website that requires local storage, with the folder name containing the name of the website, attackers can easily trace where users have been on the internet in real time.

Intercepting keystrokes and passwords

On Linux, the researchers used the “inotify” file notification system to track keystrokes within a read-protected file. Although Linux initially prevented direct monitoring on the file, it became possible as it was located in a readable folder, which allowed to spy on everything in it via the notification system. This made the keystrokes in the read-protected file visible. While the team could not see which keys had been pressed, inter-keystroke timing attacks have been around for more than two decades. Thanks to knowledge accumulated over the years, the time elapsing between individual keystrokes now reveals plenty of information.

On KDE Plasma, a popular desktop environment on Linux, the security researchers managed to overlay fake password entry windows on top of the genuine ones as soon as an authentication prompt was called up, even when the secure Wayland display server protocol was in use. To achieve this, they monitored the executable file of the “polkit” programming interface, which carries out authorisation checks. As soon as they detected an access attempt that opened a password window, the test attackers superimposed a fake password window over it so that users would enter their details there and reveal their passwords.

Data exchange via WhatsApp

On Android, the “FUSE” system is actually intended to prevent apps from accessing each other's folders. Not even the folders’ contents should be visible. However, an app without special permissions was still able to spy on activity within another app’s folder by using file notifications as a workaround. The team was thus able to observe whether images, videos and files were arriving in, being sent from or deleted from WhatsApp's folders. The researchers emphasize that they could not see the contents of these files, but they could read the file names, which might reveal something about the file’s contents and the behaviour of the user using the Android phone.

While macOS exposes the least amount of information via globally readable files, the team found that user, application, and system behaviour can still be tracked, pointing out that the macOS “FSEvents” application programming interface (API) still yields meaningful insight into user activity.

As is customary in such cases, the research team alerted the relevant teams at Linux, KDE, Android, Microsoft and Apple to the potential vulnerabilities at an early stage so they could respond before the paper was published. In collaboration with the Linux security team, patches have already been rolled out to address some of the vulnerabilities.

Publication: File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS
Authors: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast and Daniel Gruss
Available at: https://inoti.fyi 

Method of Research

Subject of Research

Article Title

Article Publication Date

AI chatbots give us a narrow slice of knowledge: Researchers warn of ‘knowledge collapse’





University of Copenhagen






“Let me just ask the chatbot.” For many of us, this has become an everyday phrase. Where we used to turn to Google to find information, AI chatbots have become a common way of getting answers to everything from what to make for dinner and how to word that difficult email to the boss, to what it actually means when interest rates rise.

But the large language models underpinning AI chatbots give us a significantly narrower range of information than a conventional web search. This is the finding of a new study led by researchers at the Department of Computer Science (DIKU) at the University of Copenhagen.

“Every language model we tested provides users with more uniform information than a simple Google search across all the topics we looked at. In other words, people are to a large extent exposed to the same information over and over again. So AI chatbots are not just changing how we find knowledge, but also which knowledge we have access to,” says first author Dustin Wright, a former postdoctoral researcher at DIKU who is now an assistant professor at Aalborg University.

At least 18% less diverse than Google

The researchers tested 27 different large language models on 155 topics. For each topic, they used 200 different prompt formulations based on questions from real users. This generated a dataset containing around 70 million individual claims produced by the models.

The results show that even the language model producing the most diverse answers – OpenAI’s GPT-5 – provides at least 18.7 per cent less varied information than Google. The topics tested by the researchers ranged from nuclear weapons, marriage, pornography, racism and genocide to more country-specific topics such as Marine Le Pen, the Falklands War and K-pop.

According to the researchers, the fact that people are increasingly using AI models as their primary gateway to information could have significant consequences:

“We risk exposing people to fewer perspectives and a narrower range of knowledge. This could create a vicious cycle in which the most popular content becomes even more dominant, while other content is increasingly overlooked,” says Professor at DIKU and senior author Isabelle Augenstein, adding:

“It’s similar to globalisation. Today, you can buy the same products and find the same coffee chains almost everywhere in the world. That has many advantages, but it has also reduced diversity.”

Why is diversity so low?

According to the researchers, the low level of diversity in language models is partly a result of how the models basically work. They compress the vast amount of text they are trained on and learn the patterns that occur most frequently. In the process, information that deviates from the most common patterns is filtered out.

The effect could be amplified if language models are increasingly trained on text produced by other AI models – something the researchers expect to happen. In that case, models would learn from their own outputs, which are already less diverse than the human-written texts on which they were originally trained.

If this process is repeated over several generations of models, the range of information could gradually become narrower. This is what the researchers refer to as ‘knowledge collapse’.

“It’s a worrying thought. However, we can see that the more recent models produce slightly more diverse answers than older models, so knowledge collapse is not happening yet. But the mechanism that could trigger it in the longer term is already there. So it is something we should be aware of,” says Isabelle Augenstein.

Seek out different sources

The researchers therefore also hope that people will use AI thoughtfully:

“AI chatbot summaries can of course be useful – that is why so many people use them. But it is still important to seek out different sources in order to understand the nuances and get a broader picture – especially for the younger generation growing up with AI. We must not become so dependent on the technology that we stop understanding and thinking for ourselves,” says Isabelle Augenstein.

The AI industry should also pay attention to the issue, the researchers argue:

“We hope AI developers will build language models in a way that preserves the breadth of knowledge available to us. We have developed a method that they can use to measure diversity in models, which could help ensure that future language models do not become less diverse,” says Dustin Wright.

 

[FACT BOX] ABOUT THE STUDY

  • The researchers analysed 27 large language models from OpenAI, Meta, Google and Alibaba.
  • The models were tested on 155 topics relating to 12 different countries.
  • The analysis covered around 1.7 million AI-generated answers and approximately 70 million individual claims.
  • The results show, among other things, that smaller AI models generate more diverse content than larger models, and that newer models are more diverse than older models. Overall, however, all the models had significantly lower diversity than traditional web search engines.
  • The research was conducted by researchers from the University of Copenhagen, Aalborg University, Stanford University, the University of Colorado Boulder and the University of Texas at Austin.
  • The study has been accepted for the international research conference EMNLP 2026, which takes place in October 2026. Read the research paper on arXiv.

 

[FACT BOX] HOW DOES AN AI CHATBOT WORK?

An AI chatbot is a service such as ChatGPT, Gemini or Claude that you can communicate with by typing or speaking and that provides answers in return. The chatbot uses a so-called large language model to understand questions and formulate responses.

A large language model is the underlying AI model that powers the chatbot. It is trained on very large amounts of text and learns patterns in how words and sentences relate to one another.

When you type a question into an AI chatbot, the chatbot sends it to the underlying large language model, which generates a response by predicting which words are most likely to fit your question.

No comments: