- Sources: primary, LWN, report, discussion
- Summary: The researchers report that read permission on a directory is enough to recover keystroke timing from
/dev/input or /dev/pts, to watch another application's private WhatsApp media folder on Android, and to identify which sites another Windows user visits. Linux carries a partial mitigation as CVE-2025-68788 in 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65, and 6.18.3. The Windows registry mitigation ships disabled by default, and Android and macOS have none. - Why it matters: The side channel needs only read permission on a directory, so sandboxing and per-app storage separation do not bound it on three of the four systems.
- Follow-up: Track an Android or macOS mitigation, whether Microsoft enables the registry setting by default, and whether the Linux fix moves from partial to complete.
send feedback on this story