# New FROST Attack Lets Websites Track Your Browsing and App Activity Through SSD Timing


A team of researchers at Graz University of Technology has demonstrated a novel side-channel attack called FROST that can identify which websites you visit and which applications you launch—all from within a malicious website's JavaScript running in your browser. The attack leaves no traces, requires no special permissions, and works on both macOS and Linux systems.


The findings, which will be presented at the DIMVA 2026 security conference, represent a significant escalation in browser-based fingerprinting techniques. Unlike previous attacks that required administrative access or special system APIs, FROST operates entirely within the browser sandbox, turning what was once a local-only threat into a remote attack that could target millions of users simultaneously.


## The Threat: A Timing Channel You Can't See


FROST exploits a fundamental property of computer storage: when multiple processes try to access a solid-state drive simultaneously, the timing of individual read operations changes in measurable ways. A malicious website can detect these timing variations through JavaScript's performance.now() timer and, using a neural network trained on timing patterns, identify with remarkable accuracy which websites or applications a user has open.


The attack is passive from the user's perspective. You visit a compromised website, and the page sits quietly in a background tab while JavaScript continuously reads from a specially crafted file on your drive. Every time you switch to another application or open a different website, the timing of those read operations shifts. The attacker's neural network translates those shifts into a catalog of your digital activity.


On macOS, the researchers achieved an 88.95% success rate identifying which of the top 50 websites a user was visiting, and 95.83% accuracy identifying native applications like Mail, Calendar, and Notes. These are not marginal numbers—they represent a nearly complete picture of a user's computing activity.


## Background and Context: The Evolution of Side-Channel Attacks


Side-channel attacks—which infer secrets from the physical properties of computation rather than cryptographic weaknesses—have long been a concern for security researchers. They've targeted power consumption, electromagnetic emissions, timing differences in cryptographic operations, and network latency. What makes FROST notable is that it brings side-channel exploitation into the browser, an environment explicitly designed to be sandboxed and restricted.


The same Graz University research group has a track record in this space. Last year, they published Secret Spilling Drive, which achieved similar results by monitoring SSD timing variations—but it required native code access through low-level Linux APIs like io_uring. FROST eliminates that requirement. The year before that, they demonstrated SnailLoad, which inferred user behavior from network latency alone without needing JavaScript. FROST represents the logical endpoint of this research: maximum impact with minimum technical barriers.


The accessibility of the attack is the critical issue. Network-level attacks require Man-in-the-Middle positioning. Native code attacks require system compromise. FROST requires only that a user visit a webpage—something billions of people do daily without suspicion.


## Technical Details: How FROST Exploits Browser Storage


The entry point for FROST is the Origin Private File System (OPFS), a browser storage API introduced in 2023 to allow web applications like cloud-based code editors and IDEs to store files locally without requesting filesystem permissions. Each website origin gets its own sandboxed slice of the filesystem, and critically, this access happens silently—no permission dialog, no user awareness.


The attacker creates a file within OPFS that is substantially larger than the system's available RAM. On Chrome and Safari, OPFS can consume up to 60% of disk space. Firefox imposes stricter limits per origin, but an attacker can distribute the file across multiple origins to bypass these restrictions.


Once the file is created, the malicious JavaScript enters a loop: it reads random 4-kilobyte chunks from this oversized file and measures the time each read takes using the browser's high-resolution timer. Because the file exceeds available RAM, the operating system cannot cache the entire file in memory, and reads must physically access the SSD.


To improve timing measurement precision, the attacker enables cross-origin isolation, a legitimate browser feature designed for different purposes, which allows more accurate timer resolution. This resolution sharpening is crucial—without it, the timing variations would be too subtle to detect reliably.


When a user opens another website or launches an application on the same physical drive, the operating system's disk I/O scheduler prioritizes those requests. This prioritization causes the attacker's carefully-timed reads to slow down in patterns that correlate with specific applications and websites. The attacker's neural network, trained on a library of these timing signatures, identifies which application or website is responsible.


### Accuracy and Scope


The researchers tested FROST across multiple scenarios:


| Test Scenario | Success Rate |

|---|---|

| Top 50 macOS websites (closed-world) | 88.95% |

| Top 50 plus 300 unknown websites (open-world) | 86.95% |

| 10 pre-installed macOS applications | 95.83% |

| Covert data channel (Linux) | 661.63 bits/second |

| Covert data channel (macOS) | 719.27 bits/second |


These results demonstrate that FROST can function both as a reconnaissance tool and as a covert communication channel between a malicious website and native code on the victim's machine.


The attack's effectiveness is limited to activity on the same physical drive as the OPFS file. Single-drive systems (most laptops) are fully exposed, while multi-drive workstations can shield activity on separate disks—though application startup sequences that access the home directory typically leak through.


## Implications for Users and Organizations


For Individual Users: FROST exposes a new vector for behavioral tracking that existing defenses do not address. Browser extensions that block tracker scripts will not help. Content blockers and cookie managers are ineffective. VPNs do not protect against a local timing side-channel. Even users who carefully configure privacy settings in their browsers remain vulnerable to this attack.


The threat is particularly acute for users who visit sensitive websites—political opposition sites, medical information resources, financial services, addiction recovery forums—or who use applications they consider private. A malicious advertisement network, compromised website, or nation-state actor with access to a major website could deploy FROST passively against millions of visitors.


For Organizations: Companies that host web applications need to understand that a compromised third-party JavaScript library or advertisement network could be used to profile their users' external computing activity. While FROST does not extract data directly from the user's machine, it creates a surveillance vector that goes far beyond traditional analytics.


Organizations should also consider that insider threats may use similar techniques to identify competitor research or confidential business applications running on shared infrastructure.


## What Browser Vendors and Regulators Are Doing


Before publication, the researchers disclosed FROST to Google, Mozilla, and Apple. The responses reveal divergent attitudes toward fingerprinting and side-channel attacks in browsers:


  • Google's Chromium team does not classify browser-based fingerprinting as a security vulnerability. The team has indicated they will not prioritize a fix.
  • Apple marked the report as "out of scope," suggesting they do not view it as a vulnerability in their products.
  • Mozilla has not publicly disclosed their response, though Firefox's lower OPFS storage limits provide marginal protection.

  • None of the browser vendors have committed to closing the OPFS access pathway or degrading timer resolution further. This likely reflects the tension between supporting legitimate web applications (like in-browser code editors that depend on OPFS) and preventing abuse.


    ## Recommendations


    For Users:

  • Be aware that malicious websites can now infer your browsing and application activity through side-channel timing attacks
  • Avoid leaving browser tabs open on unknown or untrusted websites
  • Consider additional isolation—virtual machines or separate user accounts for sensitive browsing—if you visit high-risk websites or use sensitive applications
  • Monitor for browser updates that may mitigate the underlying vulnerability

  • For Web Developers and Website Operators:

  • Audit third-party JavaScript for potential malicious behavior, particularly advertisement networks and analytics providers
  • Implement content security policies that restrict cross-origin isolation to trusted contexts only
  • Consider not enabling OPFS for non-essential use cases

  • For Organizations:

  • Assume that competitors or nation-state actors may use side-channel attacks like FROST to profile user behavior
  • Implement network segmentation if handling highly sensitive data alongside general internet access
  • Stay informed about emerging browser vulnerabilities and apply security patches promptly

  • ## HackWire Analysis


    The FROST attack is notable less for its novelty—side-channel attacks are a mature field—and more for what it reveals about the growing gap between browser security design and actual user safety. Browsers have spent a decade adding powerful APIs to support rich web applications: OPFS for local storage, high-resolution timers for performance measurement, cross-origin isolation for credential separation. Each of these features has legitimate use cases. But together, they create a complete toolkit for behavioral surveillance that operates below the threshold of traditional web security.


    What's particularly uncomfortable is the vendor response. Google does not consider this a vulnerability. Apple does not consider it in scope. Mozilla has not commented. This is not a case where vendors are "working on a fix"—it's a case where vendors have decided the threat does not meet their bar for security problems. The implication is that browser-based fingerprinting, even when it reaches the level of identifying which apps you launch, is considered acceptable.


    This represents a fundamental shift in what "browser security" means. We have historically thought of browser security as protecting against code execution, data exfiltration, or malicious script injection. FROST operates in a different layer: it infers secrets from the physical properties of computation without ever touching sensitive data directly. Defenders have no cryptographic protection against this; every bit of information that reaches your disk is vulnerable.


    The timing is also worth noting. OPFS was standardized specifically to reduce the friction of web application development. The researchers published this attack just three years after OPFS shipped in browsers. This timeline suggests that as the web platform adds more low-level capabilities, new side-channel attacks will follow rapidly. The security review process for new browser APIs may need to include threat modeling for side-channel attacks, not just traditional vulns.


    Defenders should expect more of this. The Graz group has demonstrated an intellectual pipeline: network timing → SSD timing → browser-based SSD timing. What's next? Memory latency? CPU cache contention? Power consumption? The principle is the same: physical properties of the machine leak information. As long as browsers expose high-resolution timers and powerful storage APIs, this category of attack will remain viable.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Browser Security](https://www.hackwire.news/category/browser-security) coverage
  • Cross-reference with [Privacy](https://www.hackwire.news/category/privacy) and [Fingerprinting Attacks](https://www.hackwire.news/category/fingerprinting)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)