Researchers at Graz University of Technology disclosed FROST, a browser-based side-channel attack that uses JavaScript and the browser's Origin Private File System (OPFS) to infer what websites and applications are running on a victim device. The technique requires only that a target visit a malicious webpage; the page then creates a very large OPFS file—likely 1 GB or more—and performs random reads to measure SSD latency changes caused by storage contention from other activity. Using pretrained machine-learning models, the researchers showed the attack could identify visited websites with about 89% accuracy and running applications with about 96% accuracy on an Apple M2 Mac, and said the side channel works across browsers because it relies on the storage layer rather than browser-specific behavior.
The researchers said FROST removes the need for native code or privileged kernel access used in earlier SSD side-channel attacks, though it is constrained by practical requirements, including use of the same SSD for both OPFS storage and monitored activity. They validated the latency-measurement primitive on Linux, did not test Windows, and reported no evidence of exploitation in the wild. After disclosure to Google, Apple, and Mozilla, the vendors did not commit to major fixes; Google reportedly said fingerprinting is not treated as a security vulnerability. Proposed mitigations include limiting maximum OPFS file sizes, requiring explicit permission for OPFS file creation, monitoring suspicious large OPFS files, and closing unused browser tabs.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The researchers disclosed the issue to Google, Apple, and Mozilla. According to the report, none committed to meaningful fixes, and Google said fingerprinting is not considered a security vulnerability.
In testing on Apple M2 systems, the researchers demonstrated the full attack and showed it could identify visited websites with about 89% accuracy and running applications with about 96% accuracy. They also validated the underlying latency-measurement primitive on Linux, while Windows was not tested.
Researchers described FROST, a JavaScript-based technique that uses the Origin Private File System to measure SSD contention and infer which websites and applications are active on a victim device. They reported no evidence of exploitation in the wild and said the attack works without permissions or user interaction beyond visiting a malicious webpage.
Following disclosure of the FROST browser-based SSD timing attack, Apple said it planned mitigations, while Mozilla acknowledged the issue but had not yet implemented protections. The same report said Google did not treat the technique as a vulnerability.
Researchers reported that FROST can identify device models with 88.95% accuracy and distinguish individual devices with 95.83% accuracy by measuring SSD timing through OPFS in the browser. They also demonstrated a covert channel using the same mechanism, reaching 661 bit/s on Linux and 892 bit/s on macOS.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcekaspersky.ru
Open sourcethehackernews.com
Open sourcecysecurity.news
Open sourcehannesweissteiner.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourcehannesweissteiner.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.