Published on September 24, 2026, this report, automatically translated from an LWN feed, covers research into file notification attacks on Android, Linux, macOS, and Windows. The research group published a paper and a website with details and demonstrations.
On Linux, the research describes using inotifywatch to monitor a directory and infer activity through keystroke timing, even without read access to its files. For KDE 5 and KDE 6, it reports a user-interface redirection attack: monitoring /usr/bin/pkexec to detect when Polkit opens an authentication prompt, then placing a fake window over the real one in an attempt to capture the password.
According to the report, both flaws remained present. A kernel fix partially mitigated the issue and was included in versions 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65, and 6.18.3, distributed in January. The source also mentions a mitigation intended to stop password prompt windows from losing focus.
To assess exposure, consult the original paper and demonstrations, check whether your system and KDE environment match the reported cases, and review your distribution's notes on fixed versions. Do not treat a partial mitigation as proof that all risk has been eliminated.
If using AI to study or apply the research, do not submit logs, usernames, internal paths, or other organizational data without authorization. Use fictional or anonymized examples, and verify technical guidance against the original documentation and security advisories.