Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websites you're using

TL;DR AI
2 min readKey summary
Researchers at Graz University of Technology unveiled FROST, a browser-based side-channel attack that uses JavaScript and OPFS to probe SSD timing.
By detecting latency spikes with a neural network, the technique reportedly identified websites with about 89% accuracy and apps with about 96% accuracy on a test Mac.
The attack can work across major browsers and requires only that a user visit a malicious page, with no permissions or code execution.
Major browser vendors were notified, but no fix commitment has been made, raising privacy concerns about app and site inference from browser activity.



