New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing

Using only JavaScript and the time of your SSD, a malicious website can determine which websites you browse and which apps you open. No native code, no extension, and no permission prompt are required for the FROST attack.

It monitors the disk for conflict in the background while you open the page and leave the tab open.

It was constructed by Graz University of Technology researchers, who will present their findings in a new article at DIMVA 2026. The underlying timing channel is compatible with both Linux and macOS, and it exploits a storage feature found in all major desktop browsers.

Attacks using SSD timing are not new. The same team released Secret Spilling Drive last year, which analyzes user behavior from a drive by observing how reads slow down while another device is using it.

The problem was that it required native code on the system via a low-level interface such as Linux’s io_uring. FROST removes that prerequisite. It transforms a local assault into a remote one by operating inside the browser sandbox read more about New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *