logo

Websites have a new way to spy on visitors: analyzing their SSD activity

ID: 8c2d211f-abd2-510b-897a-d0c6ce3770ca

STIX ID: report--8c2d211f-abd2-510b-897a-d0c6ce3770ca

Feed Name: Security - Ars Technica

Threat Score
30/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Dan Goodin

...
...

Researchers describe "FROST," a proof-of-concept browser-based side-channel that uses a large Origin-Private File System (OPFS) file and JavaScript to measure SSD access contention; a convolutional neural network trained on these latency traces can fingerprint active applications and websites. The attack was fully demonstrated on an M2 Mac (Linux primitive tested), has practical limitations (requires gigabyte-scale OPFS files on the same SSD, detectable at scale), no reported real-world usage, and the paper recommends mitigations such as limiting OPFS file sizes and closing unused tabs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.