The research group that found Spectre and Meltdown has published a new attack, and it needs no malware, no download, and no permission pop-up. A website you have forgotten about, sitting in a background tab, can work out which other sites you have open and which apps you are running, purely by timing how busy your SSD (solid-state drive) is. All it needs is for you to leave the tab open.
What FROST does, and how it works
Researchers at Graz University of Technology in Austria call it FROST, short for Fingerprinting Remotely using OPFS-based SSD Timing, and Dan Goodin covered it for Ars Technica on 27 May 2026. The group, led by Daniel Gruss, is the same one whose earlier work forced Intel, AMD, Apple and ARM to redesign their chips, so when this lab publishes a side-channel attack, the industry reads it carefully.
Your SSD can only handle so many requests at once, so when two programs read or write at the same moment they wait their turn, and that waiting creates tiny delays measured in millionths of a second. FROST turns those delays into a listening device. The attacker's page creates a large file in your browser's storage and reads from random spots in it over and over, timing every read. When you open a site in another tab or launch an app, that activity competes for the same drive and shows up as a spike in the timing. Each site and app loads in its own pattern, so the researchers recorded thousands of these traces, trained a neural network on them, and it can now name what caused a fresh one.
It is lip-reading for storage drives. The attacker never sees your files or your screen, only how hard your drive is working. Tested against the 50 most popular websites, the model named the right one about nine times out of ten (an F1 score of 88.95 percent). Against 10 everyday Mac apps, including Maps, Music and System Settings, it named the right one roughly 95 times out of 100.
Why there is no patch coming
What makes this unsettling is that nothing is broken. FROST abuses a normal browser feature called OPFS, the Origin Private File System: a private storage area that browsers hand to every site automatically with no prompt, so web apps like online editors can save data on your machine. Chrome, Firefox and Safari have supported it since around 2023. It was built for speed, skipping checks that slower file access goes through, and that speed is what makes precise timing possible. A computer normally caches recent reads in memory (RAM) to avoid touching the slow disk twice, which would hide the signal, so FROST writes a file bigger than the machine's whole memory and forces nearly every read down to the drive. Chrome and Safari let one site claim up to 60 percent of the disk, enough for a 38 GB file on a 64 GB laptop. And because the bottleneck is the drive itself, below the browser, a spy page in Chrome can read your activity while you work in Safari on the same laptop.
The researchers disclosed to Google, Mozilla and Apple before publishing, and the replies explain why a quick fix is unlikely. Google's Chromium team does not treat fingerprinting as a security vulnerability, so Chrome is not patching this. Apple called it out of scope for now, with no date attached. Mozilla acknowledged the findings and has shipped nothing. The paper lists fixes they could adopt, from capping that storage so the file fits in memory to asking your permission before a site uses OPFS, but each one slows the feature down, which is why none has shipped.
There is one important limit. The attack was demonstrated on a Linux desktop and an Apple M2 Mac mini; Windows was not tested. OPFS exists on Windows too, so treat Windows as unproven rather than immune, and do not read "not tested" as "not affected".
Why this matters for South African businesses
Out of the lab, FROST is a tracking method, and a quiet one. Most tracking you can fight by clearing cookies or blocking trackers, but FROST leaves nothing to grab hold of, because the page is only timing its own storage. It can build a picture of what someone does on a device without consent and without anything you would recognise as surveillance.
Under POPIA, the Protection of Personal Information Act, a business that handles other people's personal information must apply reasonable safeguards to it, and covert profiling of the kind FROST enables is the silent data harvesting the Act exists to push back against. Picture a staff member running your business banking or a client's SARS eFiling in one tab while 40 tabs from this morning sit open beside it, one of them quietly profiling the machine. The distance between what you allowed and what is happening is the gap POPIA asks you to close.
The harder truth for a business owner is that the tools you bought do not help here. Your antivirus is hunting for malware that does not exist, your extension blocker for rogue add-ons that were never installed, so nothing is breached and nothing trips an alarm. The only defence is how your team uses the browser, which makes this a training and habit problem, not a software purchase.
What to do this week
The practical defences are unglamorous, and they work. The attack only runs while its tab is open, and only while your activity lands on the same drive it is watching.
- Close the tabs you are not using. The moment the spy page is closed, the attack stops, so a browser full of forgotten tabs is the ideal home for it. Make closing tabs a daily habit rather than an occasional clear-out.
- Keep sensitive work on its own. When you are in business banking, SARS eFiling, or anything touching client data, do it in a single tab in a single window with nothing else open beside it. On its own, that removes the side channel.
- Watch your disk space. FROST needs a very large file, tens of gigabytes, to work, so storage filling up for no reason you can explain is a warning sign. Browsers do not show this clearly, so you have to check your system storage settings yourself.
- Make browser habits part of staff training. Since no product stops this, the people at the keyboard are the control. A short, plain session on closing tabs and separating sensitive sessions does more here than anything you could install.
Where Ubuntu Guard fits
If you have never looked at how your team's browser and device habits expose your business, that is the ground our cybersecurity assessment covers. We map what sits on those machines, what they can reach, and where POPIA obligations meet everyday habits like leaving tabs open next to sensitive work. The report is plain language and the output is a short list of what to change and in what order.
Not sure what your team's everyday browsing exposes? WhatsApp us and we will walk you through the next step, or reach us at [email protected].
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za