FROST Attack Tracks Sites and Apps You Open

FROST Attack Creates New Privacy Risks

FROST Attack is a new technique that threatens user privacy. Researchers recently revealed how it works through web browsers. Unlike older attacks, it requires only JavaScript. Therefore, attackers do not need special software or permissions.

A user simply opens a malicious website. The page then remains active in the background. Meanwhile, it monitors storage activity on the device. As a result, it can gather information about user behavior. Researchers developed FROST Attack using browser-based features. The attack operates entirely within the browser sandbox. Therefore, attackers no longer need local access to a device.

Earlier SSD timing attacks required native code. However, FROST removes that limitation completely. As a result, attackers can launch the attack remotely. This change significantly increases the potential risk.

OPFS Enables the Technique

The attack relies on the Origin Private File System, or OPFS. Browsers introduced this feature to support advanced web applications. For example, online editors can save files directly on a device.

OPFS gives websites access to dedicated storage areas. Furthermore, it does not require user permission prompts. Therefore, a malicious website can start writing data immediately. This behavior creates an opportunity for abuse. Normally, operating systems hide disk activity through caching. Frequently accessed files stay in memory. As a result, storage timing becomes difficult to measure.

However, FROST works around this limitation. The attack creates files larger than available memory. Therefore, storage requests continue reaching the SSD. This allows attackers to monitor timing changes more effectively.

Measuring SSD Activity

The attack repeatedly reads small chunks of data. Meanwhile, it measures how long each read operation takes. Therefore, it can detect changes in storage performance.

Browser timers usually reduce measurement accuracy. However, attackers can improve timing precision using browser features. As a result, they obtain more detailed information. This improves the effectiveness of the attack.

User Activity Reveals Patterns

When users open websites or applications, storage activity increases. Consequently, the attacker’s measurements change noticeably. Researchers then use machine learning models to analyze these patterns.

The system compares timing information against known profiles. Therefore, it can identify websites and applications with high accuracy. This process creates a powerful fingerprinting technique. Tests showed impressive results on macOS systems. For example, the attack identified popular websites with accuracy above 88%. Furthermore, application detection reached more than 95%.

Researchers also demonstrated a covert communication channel. Therefore, data moved between applications and browser pages through storage timing signals. Although transfer speeds remained limited, the results were still concerning.

Some Limitations Exist

FROST Attack does not affect every situation equally. The attack only detects activity occurring on the same storage device. Therefore, separate drives can reduce exposure. Multi-drive systems provide additional protection. However, many laptops use a single storage device. As a result, a large number of users remain vulnerable to this technique.

Researchers notified major browser developers before publication. However, no complete fix currently exists. Therefore, users have limited protection options today.

Some developers do not classify fingerprinting as a security vulnerability. Others have acknowledged the findings without releasing updates. As a result, the issue remains unresolved.

Possible Future Solutions

Several mitigation strategies have been proposed. For example, browser developers could limit OPFS storage size. Therefore, attackers would struggle to create oversized files. Developers could also reduce timer precision further. In addition, browsers could require permission before OPFS access. However, these changes may affect performance and usability. Therefore, implementation remains uncertain.

FROST Attack highlights a growing challenge in browser security. Modern web applications increasingly gain access to hardware features. As a result, new privacy risks continue to emerge.

Researchers believe the broader trend deserves attention. Therefore, security discussions should focus on future browser capabilities. The concern extends beyond a single attack technique. It reflects a larger shift in web technology.

How to Prevent FROST Attack Risks

Users should close suspicious browser tabs and avoid untrusted websites whenever possible. In addition, organizations should continuously monitor endpoint activity for unusual behavior. Managed detection and response services can help identify emerging threats and investigate suspicious events quickly.

Furthermore, regular security assessments can uncover browser-related risks before attackers exploit them. Together, these measures improve visibility and strengthen protection against advanced privacy-focused attacks.

Sleep well, we got you covered.

Scroll to Top