iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› New FROST Attack Spies on Websites and Apps Through SSD Timing

New FROST Attack Spies on Websites and Apps Through SSD Timing

Researchers have discovered a new side-channel attack named FROST that uses JavaScript and OPFS to measure SSD contention, allowing websites to infer other sites and apps running on a device. The attack requires a large OPFS file and has limitations but poses a privacy risk. Enterprise users should be aware and limit browser tab usage.

iG
iGEN Editorial
June 14, 2026
New FROST Attack Spies on Websites and Apps Through SSD Timing

A new technique named FROST (Fingerprinting Remotely Using OPFS-based SSD Timing) allows websites to spy on visitors by measuring subtle interactions with their solid-state drives, according to research reported by WIRED. The attack enables sites to monitor other websites a visitor is viewing and what apps are open on their device—all without requiring any interaction beyond opening the malicious site.

How FROST Works

FROST exploits a contention side channel, a form of leak resulting from physical manifestations such as the time required to complete a task. By measuring the timing of certain I/O operations on the visitor's SSD, researchers were able to determine the websites open in other tabs—even on other browsers—and the apps open on the device. The attack runs entirely in the browser using JavaScript that interacts with the OPFS (origin private file system), an allocated storage space reserved for a specific site. Websites can create an OPFS file with no user interaction.

While each OPFS is sandboxed and isolated from other sites and the device system, the JavaScript can measure I/O interactions. Those measurements are then run through a pretrained convolutional neural network (CNN)—a deep learning system used to analyze text, audio, and images—to deduce the various apps and websites open on the device. As the researchers explained: "The attacker continuously measures SSD contention by performing random reads from a large OPFS file. SSD contention caused by user activity causes measurable latency differences for these read operations. By training a convolutional neural network (CNN) on these traces, the attacker can fingerprint user activity on the host system by classifying new traces using the trained model."

Limitations of the Attack

FROST has several limitations that reduce its practical threat at scale. First, the OPFS file must be extremely large—likely a gigabyte or more—which would be detected by many users. Second, the OPFS file must be stored on the same SSD the visitor is using. This works for tracking open websites since the browser's default location uses the system drive, but if apps reside on a separate SSD drive, they cannot be detected.

Defensive Measures

One of the simplest ways to prevent FROST attacks is to close tabs as soon as they are no longer needed. More technically savvy users can monitor the creation and size of OPFS files allocated by unknown websites. The researchers also proposed that browser makers could shut down this side channel by, for example, limiting the maximum size of such OPFS files.

Implications for Enterprise Cybersecurity

For enterprise technology leaders—particularly those managing supply chain systems that rely on browser-based applications—this attack vector underscores the growing attack surface of modern browsers. The researchers noted: "Web browsers have evolved from simple document viewers into complex platforms capable of running sophisticated applications. Companies like Google, Microsoft, and Adobe have developed full-fledged office suites, photo- and video editors, or even integrated development environments (IDEs) that run entirely within the browser." These capabilities, while powerful, "also increase the browser's attack surface, and some have already been shown to introduce new vulnerabilities."

Attack Feature Description
Technique FROST (Fingerprinting Remotely Using OPFS-based SSD Timing)
Vector Contention side channel via SSD I/O timing
Required Resource Large OPFS file (1 GB+)
Detection Difficulty Low for normal users; OPFS size may alert careful users
Mitigation Close unused tabs; monitor OPFS allocations; browser-level size limits

While this specific attack has not been observed in the wild, it demonstrates the continued evolution of browser-based surveillance methods, previously seen with techniques targeting browsing histories, device fingerprints, and real-time keystroke monitoring. Even major firms like Meta and Yandex have been caught engaging in privacy-invasive tracking, according to the report. Enterprises should review their browser security policies and consider restricting OPFS usage or limiting the storage quota for third-party sites.


Sources:

Keep Reading

Recommended Stories

Reverse-Lookup Service Exposed Millions of Photos of People's Faces Technology

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Independent security researcher Jeremiah Fowler found that the people-search service ClarityCheck left more than 9 million image files, including photos of faces, publicly accessible in an unsecured Amazon S3 bucket. A second misconfiguration exposed email addresses and phone numbers. The company secured the data after WIRED reached out but disputed that the data was publicly exposed.

August 19, 2026
EU Politician Investigating Pegasus Spyware Was Hacked With the Same Malware, Citizen Lab Finds Technology

EU Politician Investigating Pegasus Spyware Was Hacked With the Same Malware, Citizen Lab Finds

A new analysis by Citizen Lab reveals that Greek MEP Stelios Kouloglou, a member of the European Parliament's PEGA Committee investigating Pegasus spyware, had his iPhone hacked multiple times with the same spyware. The incident marks the first time a committee member has been identified as a victim and highlights the brazen targeting of European lawmakers. Researchers could not identify the attacker but warn of severe security implications for parliamentary work.

July 3, 2026
Incogni Report Reveals Job-Search Platforms Selling User Data Without Awareness Technology

Incogni Report Reveals Job-Search Platforms Selling User Data Without Awareness

A new report from Incogni reveals that leading job-search platforms are selling users' sensitive data to third parties, often without users' awareness. ZipRecruiter, LinkedIn, and Monster rank highest for data collection and sharing. Only 7% of surveyed job seekers expressed concern about privacy risks.

June 15, 2026
CBP Workers Allegedly Used Government Databases to Spy on Exes and Colleagues Regulations & Compliance

CBP Workers Allegedly Used Government Databases to Spy on Exes and Colleagues

WIRED obtained internal records showing hundreds of allegations that CBP employees and contractors misused government databases for personal reasons, from romantic inquiries to tracking coworkers. The alleged misconduct spans 2009–2022 and includes referrals to criminal investigators. A DHS employee's use of ad-tech location data to track coworkers is the first known internal abuse case of its kind.

August 13, 2026