logo

Websites can spy on user activity by analyzing SSD behavior

ID: 63121504-49b7-5907-9110-77a7bc22f6c2

STIX ID: report--63121504-49b7-5907-9110-77a7bc22f6c2

Feed Name: Help Net Security

Threat Score
35/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Sinisa Markovic

...
...

FROST is a proof-of-concept side-channel attack that leverages the browser's Origin Private File System (OPFS) to measure SSD contention timing from JavaScript, enabling remote fingerprinting of websites and applications on the same SSD; the technique requires only visiting a malicious webpage, has practical limits (large OPFS files, same-drive requirement), and researchers responsibly disclosed findings to browser vendors who are evaluating mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.