BlackTree Security · Infrastructure · Automation · AI

Even Protected Files Can Give Away What You Are Doing

Researchers at Graz University of Technology show that filesystem notifications can reveal user activity even when a process cannot read the underlying file. Their ACM CCS 2026 paper covers Linux, Windows, macOS and Android. Most desktop demonstrations require malicious code already running locally without elevated privileges.

The experiments inferred typing rhythms, browsing and application activity. Linux keystroke-timing tests reached F1 scores of 93.1% to 100%; that is not direct recovery of typed text. Android tests used an installed app without requested permissions. Windows exposed paths across user boundaries, while macOS leaked less. The paper reports partial Linux fixes under CVE-2025-68788. These are laboratory results, not evidence of widespread exploitation.

Access control should account for observation

The practical question for a shared system is not only which files a user can open. It is also which events that user’s processes can observe. Timing and path metadata can reveal a working pattern even when the protected document stays closed.

For a high-trust administrative workstation, reducing untrusted local software can therefore matter as much as protecting the document store. On a shared research or development host, review whether separate users are intended to be mutually distrusting and whether the isolation design supports that assumption.

Measure the right outcome

Do not turn an experimental detection score into a password-recovery rate or a promise that a patch eliminates every related channel. Ask which primitive the vendor fixed, which platform versions were tested and which residual observations remain possible. Re-test the required boundary using benign test accounts and synthetic activity rather than collecting real users’ sensitive behaviour.

What defenders can do

  • Update Linux kernels. The canonical record for CVE-2025-68788 identifies fixed stable releases including 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64 and 6.18.3. Distribution guidance takes precedence for packaged kernels.
  • Reduce untrusted local code. Application allow-listing, mobile application controls and strong software provenance reduce the chance that a low-privilege observer is present.
  • Review shared-host assumptions. Separate tenants and sensitive administrators where timing and activity metadata would be valuable.
  • Use confinement as defence in depth. Containers, sandboxes and mandatory access controls should restrict which paths an untrusted process can observe, while recognising that the paper also found container and VM activity signals.
  • Do not log away the privacy problem. File-event telemetry can aid detection, but collecting more path and activity data creates its own access-control and retention obligations.
  • Treat UI timing as a trust signal. Authentication prompts should make their origin verifiable and resist overlays, rather than relying only on appearing at an expected moment.

BlackTree has previously covered Tontou’s timing gap in Spectre V2 defences. The new work reaches a different layer: the operating system itself provides the event stream. The broader lesson is the same. A boundary can hide content while still leaking enough structure to reveal behaviour.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *