FROST: A Browser Attack That Exploits SSD Timing to Spy Across Tabs and Apps

FROST: A Browser Attack That Exploits SSD Timing to Spy Across Tabs and Apps

Researchers at Graz University of Technology have unveiled FROST, a side-channel attack that allows websites to monitor visitor activity across browser tabs and even identify applications running outside the browser. The attack works by measuring SSD input-output timing patterns through JavaScript, exploiting the Origin Private File System API. FROST creates storage contention, then uses a neural network to fingerprint concurrent system activity from timing variations alone.

Published

Read at another depth