FROST Attack: A Website Is Watching Your SSD Blink And You Don't Even Know It
Oh good. Another attack that requires absolutely nothing from the attacker and absolutely nothing from the flock either. No fake grain, no suspicious links, no "click here to claim your free hay." Just open a tab and sit there like the oblivious lamb you are.
Researchers at Graz University of Technology, who clearly hate everyone's weekend, built something called FROST. A malicious page can fingerprint which other sites you visit and which apps you have open, just by watching your SSD sweat. It measures drive contention timing through plain JavaScript. No native code, no browser extension, no permission prompt. Nothing.
You literally just have to open the page.
That's it. That's the whole user error. Existing.
The wolves don't need to lure you with fake grain anymore. They just need you to wander near their pasture once, and they can watch the flicker in your hoofsteps and reconstruct your entire browsing history. "Oh interesting, this lamb has seventeen crypto tabs open and a gambling app running. Let's have a chat."
And the best part? The tab doesn't even need to be in focus. It just sits there in the background, quietly timing your drive like a very patient coyote with a stopwatch and a spreadsheet.
I have been awake for thirty hours and this is what I'm reading.
The Shepherds, naturally, will ask if we can solve this with a policy. We cannot solve this with a policy. We cannot solve this with a strongly worded email to the flock either, though I will be sending one anyway because what else am I going to do.
This is a browser-level, hardware-level, "the architecture of computing is your enemy" kind of problem. Those are my favorite kind. Really fills the soul.
Remediation
Look, I'm not going to pretend there's a clean fix here. There isn't.
For the flock: Stop having forty tabs open. I know you won't. But I said it.
For the technically inclined: Isolate your browsing. Use separate browser profiles or dedicated VMs for sensitive sessions. The sheep tunnel helps with network-level snooping but does nothing for local timing attacks, so don't go feeling smug.
For browser vendors: Site isolation and high-resolution timer restrictions exist for a reason. FROST is a reminder to keep tightening those screws. Coarsen those timers further. Make the SSD signals noisier. Make the coyote's stopwatch useless.
For the Shepherds: No, buying a new SSD will not fix this.
I'm going back to staring at my monitoring dashboard and pretending I'm fine.
Original Report: https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html