Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FROST Attack Exploits SSD Timing to Track Website Visits

FROST Attack Exploits SSD Timing to Track Website Visits

Posted on June 9, 2026 By CWS

A newly identified threat, known as the FROST attack, allows malicious websites to monitor which sites you visit and apps you use by analyzing SSD timing. This sophisticated method, developed by researchers from Graz University of Technology, operates using JavaScript without requiring native code or special permissions.

Mechanism of the FROST Attack

FROST functions by exploiting the Origin Private File System (OPFS), a browser feature designed to help web applications store files locally. By creating files that exceed the device’s RAM, FROST forces the system to read directly from the SSD, allowing attackers to measure timing discrepancies. These discrepancies can reveal activity when a user opens websites or applications, which the attacker’s neural network can identify with high accuracy.

This attack is a progression from previous methods like the Secret Spilling Drive, which required native code and lower-level system access. By running entirely within the browser’s sandbox, FROST transforms a local threat into a remote one, broadening its potential impact.

Impact and Accuracy

The precision of FROST is notably high. Tests on macOS revealed an F1 score of 88.95% for identifying the top 50 websites during closed-world tests, and 86.95% in open-world scenarios involving 300 unfamiliar sites. When targeting ten native macOS applications, the accuracy reached 95.83%. Additionally, the technique can serve as a covert communication channel, although it’s currently limited to activities occurring on the same drive as the OPFS file.

While the attack has been verified on macOS, its full capabilities remain untested on other platforms. The approach primarily affects single-drive systems, as multi-drive setups can obscure activity occurring on different drives.

Current Defenses and Future Outlook

As of now, there are limited defenses against FROST. Although Google, Mozilla, and Apple have been informed, responses vary from acknowledgment to considering future mitigations. Users can mitigate risk by closing suspect browser tabs and monitoring for large unexplained files. However, the primary solution lies with browser developers, who need to implement measures like OPFS size limits or enhanced permission protocols.

The debate persists on whether such tracking capabilities are a flaw or an inherent feature of modern browser design. The researchers express concern over the growing trend of browsers granting web apps extensive access to hardware, leading to increased potential for privacy breaches. Monitoring this pattern is crucial for future cybersecurity efforts.

The Hacker News Tags:browser vulnerabilities, Cybersecurity, FROST attack, Graz University, JavaScript, Linux, macOS, SSD timing, Tracking, web security

Post navigation

Previous Post: AI’s Impact on the Future of Bug Bounties
Next Post: Claude Mythos Revolutionizes Exploit Creation with AI

Related Posts

Chinese Cyber Group Exploits Google Workspace to Steal Emails Chinese Cyber Group Exploits Google Workspace to Steal Emails The Hacker News
Chinese Hackers Target Taiwan’s Semiconductor Sector with Cobalt Strike, Custom Backdoors Chinese Hackers Target Taiwan’s Semiconductor Sector with Cobalt Strike, Custom Backdoors The Hacker News
CloudZ Malware Exploits Phone Link for Credential Theft CloudZ Malware Exploits Phone Link for Credential Theft The Hacker News
Majority of iOS AI Apps Expose Vulnerable API Keys Majority of iOS AI Apps Expose Vulnerable API Keys The Hacker News
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code The Hacker News
How To Browse Faster and Get More Done Using Adapt Browser How To Browse Faster and Get More Done Using Adapt Browser The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark