New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing
Using only JavaScript and the time of your SSD, a malicious website can determine which websites you browse and which apps you open. No native code, no extension, and no permission prompt are required for the FROST attack.
It monitors the disk for conflict in the background while you open the page and leave the tab open.
It was constructed by Graz University of Technology researchers, who will present their findings in a new article at DIMVA 2026. The underlying timing channel is compatible with both Linux and macOS, and it exploits a storage feature found in all major desktop browsers.
Attacks using SSD timing are not new. The same team released Secret Spilling Drive last year, which analyzes user behavior from a drive by observing how reads slow down while another device is usi...

