Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers report that Microsoft considers the side-channel leak of file events to be by design
Security researchers from Austria's Graz University of Technology have discovered vulnerabilities in the file notification systems of Android, Linux, macOS, and Windows. These flaws allow potentially sensitive system information to be leaked, posing a significant security risk. The file notification subsystems in each operating system are designed to inform applications when files change.
However, these systems can be exploited by malicious users to infer activities of other users on the computer, potentially enabling inter-keystroke-timing attacks, website fingerprinting, and UI redress attacks leading to credential theft. The vulnerabilities affect systems that were first implemented in 2005 for Linux, 2008 for Android, 2000 for Windows, and 2007 for macOS.
While mitigation measures have been partially implemented for Linux, no fixes have been applied to Android devices. The researchers warn that these file notification attacks affect all major operating systems and call for further mitigations, such as extending capability checks and introducing a permission system within the kernel.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.