File‑Notification APIs on Windows, Linux, and macOS Enable Unprivileged Accounts to Spy on Other Users (CVE‑2025‑68788)
What Happened — Researchers at Graz University of Technology demonstrated that the file‑notification mechanisms built into Windows (ReadDirectoryChangesW), Linux (inotify) and macOS (FSEvents) can be leveraged by a standard, unprivileged account to observe the activity of other users on the same host. By watching file‑system events in directories the attacker can infer web‑site visits, keystroke timing, and other user actions with >95 % accuracy on Firefox and >90 % on Linux SSH sessions.
Why It Matters for Trust & Control Assurance
- The technique bypasses traditional user‑level isolation, exposing a gap in access‑control segregation that continuous‑control programs are designed to detect and remediate.
- Evidence of such cross‑account observation can be captured as part of an audit‑ready control‑monitoring log, providing defensible proof that segregation‑of‑duties policies are enforced.
- Verisq’s Access Controls capability helps map this OS‑level weakness to the relevant control objective and supplies the evidence needed for NIST CSF 2.0 or ISO 27001 assessments.
Who Is Affected
- Enterprises and service providers running Windows 11 24H2, modern Linux distributions, or macOS 13+.
- Any organization that permits unprivileged accounts to create broad directory watches (e.g., development workstations, shared servers, CI/CD runners).
Recommended Actions
- Review OS‑level file‑notification permissions and restrict watch capabilities to privileged service accounts only.
- Deploy monitoring that flags unusually high volumes of directory‑watch events originating from non‑admin accounts.
- Apply any vendor patches that address CVE‑2025‑68788 as soon as they are released.
- Document segregation‑of‑duties controls and collect evidence of compliance for audit readiness.
Source: Help Net Security
Technical Notes
- Attack vector: Abuse of OS file‑notification APIs (ReadDirectoryChangesW, inotify, FSEvents).
- Impact: Enables covert profiling of browsing, keystroke timing, and application usage across user boundaries.
- Performance: The monitoring overhead was measured at ≤0.21 % CPU on the tested platforms.
Source: Help Net Security