‘Decades-old’ bugs found affecting Windows, Android, macOS and Linux, but OS makers don’t see it as a big deal


  • Researchers at the University of Graz found decades-old flaws in file notification subsystems in Linux, Windows, macOS and Android
  • Side-channel attacks can infer keystrokes, websites visited, or even steal credentials through unprivileged access.
  • Linux submitted partial mitigations (CVE‑2025‑68788); Microsoft and Apple acknowledged this but did not implement the patch; Demonstration expected at ACM CCS 2026

Researchers have found a vulnerability in all major operating systems that could, in certain scenarios, allow threat actors to steal login credentials or track which websites the target is visiting. Operating system manufacturers, on the other hand, don’t seem too far ahead in this regard.

The bug is described as a side-channel attack, a type of attack in which threat actors simply observe how the system works and extract valuable secrets through indirect clues. For example, by monitoring how much power the chip consumes at any given time, attackers can observe and extract passwords.

Avatar photo

Miraj Islam is a writer and contributor at Oalanbrado, interested in news, current events, technology, lifestyle, and stories that matter to readers. He enjoys researching different topics and turning information into clear, useful, and engaging articles. Through his work, Miraj aims to keep readers informed with fresh perspectives and easy-to-understand content from Brazil and around the world.

Post Comment