Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

File‑Notification APIs on Windows, Linux, and macOS Enable Unprivileged Accounts to Spy on Other Users (CVE‑2025‑68788)

Researchers showed that OS file‑notification mechanisms (ReadDirectoryChangesW, inotify, FSEvents) allow an unprivileged account to infer another user’s web visits and keystroke timing. The flaw affects Windows, Linux and macOS installations and highlights a critical access‑control gap that must be evidenced for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
helpnetsecurity.com

File‑Notification APIs on Windows, Linux, and macOS Enable Unprivileged Accounts to Spy on Other Users (CVE‑2025‑68788)

What Happened — Researchers at Graz University of Technology demonstrated that the file‑notification mechanisms built into Windows (ReadDirectoryChangesW), Linux (inotify) and macOS (FSEvents) can be leveraged by a standard, unprivileged account to observe the activity of other users on the same host. By watching file‑system events in directories the attacker can infer web‑site visits, keystroke timing, and other user actions with >95 % accuracy on Firefox and >90 % on Linux SSH sessions.

Why It Matters for Trust & Control Assurance

  • The technique bypasses traditional user‑level isolation, exposing a gap in access‑control segregation that continuous‑control programs are designed to detect and remediate.
  • Evidence of such cross‑account observation can be captured as part of an audit‑ready control‑monitoring log, providing defensible proof that segregation‑of‑duties policies are enforced.
  • Verisq’s Access Controls capability helps map this OS‑level weakness to the relevant control objective and supplies the evidence needed for NIST CSF 2.0 or ISO 27001 assessments.

Who Is Affected

  • Enterprises and service providers running Windows 11 24H2, modern Linux distributions, or macOS 13+.
  • Any organization that permits unprivileged accounts to create broad directory watches (e.g., development workstations, shared servers, CI/CD runners).

Recommended Actions

  • Review OS‑level file‑notification permissions and restrict watch capabilities to privileged service accounts only.
  • Deploy monitoring that flags unusually high volumes of directory‑watch events originating from non‑admin accounts.
  • Apply any vendor patches that address CVE‑2025‑68788 as soon as they are released.
  • Document segregation‑of‑duties controls and collect evidence of compliance for audit readiness.

Source: Help Net Security

Technical Notes

  • Attack vector: Abuse of OS file‑notification APIs (ReadDirectoryChangesW, inotify, FSEvents).
  • Impact: Enables covert profiling of browsing, keystroke timing, and application usage across user boundaries.
  • Performance: The monitoring overhead was measured at ≤0.21 % CPU on the tested platforms.

Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/28/cve-2025-68788-file-notification-attacks/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →