SIGNALInfrastructure Software·May 28, 2026, 1:10 PMSignal75Short term

Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websites you're using

Source: Tom's Hardware

Share
Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websites you're using

FROST exploits the Origin Private File System (OPFS), a browser API that lets websites create and store files on a user's local disk.

Why this matters
Why now

This attack vector has emerged due to the increasing reliance on browser APIs for local storage and the ongoing quest for new methods of user tracking by malicious actors, alongside the continuous research into system-level side-channel attacks.

Why it’s important

This development highlights a critical vulnerability in fundamental web security, as it allows for pervasive user tracking without consent or detection, undermining privacy and data security assumptions from leading tech vendors.

What changes

The understanding of browser security models must adapt to include side-channel attacks through hardware interaction, requiring browser developers to re-evaluate the isolation and permissions of low-level APIs.

Winners
  • · Cybersecurity researchers
  • · Privacy-focused browser developers
  • · Ethical hacking firms
Losers
  • · Users of mainstream browsers
  • · Developers relying on OPFS for privacy-sensitive data
  • · Web advertising industry (if mitigated effectively)
  • · Tech companies with privacy commitments
Second-order effects
Direct

Major browser vendors will prioritize patching or re-architecting the OPFS or similar APIs to mitigate this attack.

Second

An increase in demand for advanced privacy tools and services that actively mask or randomize SSD activity and other side-channel leakage.

Third

Potential regulatory pressure on browser and operating system developers to implement stronger hardware-level side-channel protection in consumer products.

Editorial confidence: 90 / 100 · Structural impact: 55 / 100
Original report

This signal links to a primary source. Continuum Brief monitors and indexes it as part of the live intelligence stream — we do not republish source content.

Read at Tom's Hardware
Tracked by The Continuum Brief · live intelligence network
Share
The Brief · Weekly Dispatch

Stay ahead of the systems reshaping markets.

By subscribing, you agree to receive updates from THE CONTINUUM BRIEF. You can unsubscribe at any time.