'Decades-old' bugs found affecting Windows, Android, macOS and Linux — but the OS makers don't see it as a big deal
Microsoft even said it was by design
by https://www.techradar.com/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 25 September 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Graz University researchers found decades‑old flaws in file‑notification subsystems across Linux, Windows, macOS, and Android
- Side‑channel attacks can infer keystrokes, visited websites, or even steal credentials via unprivileged access
- Linux shipped partial mitigations (CVE‑2025‑68788); Microsoft and Apple acknowledged but did not patch, demo expected at ACM CCS 2026
Researchers have found a vulnerability in all major operating systems which could, in certain scenarios, allow threat actors to steal login credentials, or track which websites the target is visiting. OS makers, on the other hand, don’t seem all too phased about it.
The bug is described as a side-channel attack - a type of attack in which threat actors simply observe how the system operates and extract valuable secrets through indirect clues. For example, by monitoring how much power the chip takes at any given moment in time, attackers can observe and extract passwords.
It was discovered by security researchers from Austria’s Graz University of Technology: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast, and Daniel Gruss.
Latest Videos FromTechRadarWatch full video here:
Notifying the system
This particular side-channel vulnerability was found in the file-notification subsystem running in pretty much every OS in existence today. The subsystem is built to notify applications when files on a system change. Not what has changed, just that a change occurred. The bug is allegedly quite old, too.
"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change," said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to The Register.
On Linux, the subsystem is called inotify and it’s been affected since 2005. On Android it’s FileObserver (affected since 2008), and on Windows - ReadDirectoryChangesW - flawed since the year 2000. On MacOS, it’s called FSEvents, vulnerable since 2007.
In the paper, the researchers claim file event information can help attackers conclude what other users on a computer are doing. They can launch an inter-keystroke-timing attack, inferring what users are inputting (both locally and remotely), reveal which websites they visit, and possibly even steal login credentials through UI redress.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors