logo

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing

ID: 27c60505-20e5-5da8-8309-9c3ad6510dc5

STIX ID: report--27c60505-20e5-5da8-8309-9c3ad6510dc5

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: [email protected] (The Hacker News)

...
...

FROST is a browser-only SSD timing side-channel that abuses OPFS to force disk reads from a large attacker-owned file and measures contention via high-resolution timers in JavaScript to fingerprint visited websites and native apps; Graz University researchers demonstrate high classification accuracy on macOS and a covert channel for data transfer, note no evidence of in-the-wild use, and recommend mitigations such as capping OPFS size, throttling timers, or adding permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.