Skip to main content
  1. Home
  2. Computing
  3. News

Your hard drive is giving away your browsing habits and websites can see it

A new attack called FROST lets malicious websites spy on your open tabs and apps by tracking your SSD activity.

Add as a preferred source on Google
An SSD data port.
Bdavid32/Shutterstock

Your browsing habits may not be as private as you think, even with all the right precautions in place. According to Ars Technica, security researchers have uncovered a new attack technique that lets a malicious website figure out which other sites and apps you have open. You do not need to click anything, download anything, or grant any permission; just visiting the page is enough.

How can websites spy on your browsing activity through hard drive?

The technique is called FROST, short for Fingerprinting Remotely using OPFS-based SSD Timing. Every website and app you use generates its own unique pattern of activity on your SSD, the storage drive inside your computer.

Recommended Videos

FROST exploits a browser feature called the Origin Private File System, or OPFS, which quietly lets websites store files on your local drive without asking permission first.

The attacker’s page creates a large file on your drive and then listens to the tiny speed fluctuations that happen when your SSD is busy handling other tasks. Those fluctuations are fed into an AI model that has been trained to recognize the telltale patterns of specific websites and apps.

According to the research paper, the technique correctly identified which websites a person had visited with about 89% accuracy, and which apps were running with about 96% accuracy, when tested on an Apple M2 Mac.

The attack also works across different browsers simultaneously, meaning visiting the attacker’s page in Chrome can still expose what you are doing in Safari.

The browsers won’t fix this, but you can protect yourself

FROST has not been spotted in the wild yet, which is reassuring. It also only works while the offending tab is open, so closing it immediately stops the attack.

Google, Apple, and Mozilla were all informed, but none have committed to a fix. Your best defense right now is keeping an eye on your available disk space. A sudden, unexplained drop in storage is a red flag worth investigating immediately.

Browser-level fixes have been proposed, including capping how much disk space OPFS can claim, but given the browser makers’ responses, those changes are not coming any time soon.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt
The price hike could touch every Snapdragon-powered device category.
The new Qualcomm Snadragon 8 Elite Gen 5

I want you to sit with this for a second. Qualcomm, the company whose Snapdragon chips sit inside your Android phone and tablet, your Windows laptop, your Meta smart glasses, your Galaxy Watch, and your wireless earbuds, reportedly sent a letter to every major customer telling them prices are going up by double digits. 

The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price. 

Read more
Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school
One plug, zero drama, all your devices charged by morning.
Satechi ChargeView

Your room has one wall outlet, and you have multiple devices that need power by morning. Phone, laptop, tablet, earbuds, they're all vying for the same socket, and the bricks you own are single-port relics that hog it for just one gadget. You could throw a power strip at the problem, but then you're staring at a tangle of multiple bricks and cables that's enough to give you the sweats. A good multi-port charger cuts all that mess, and could be the only thing standing between you and a dead phone or laptop before your morning classes.

Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.

Read more
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
OpenAI’s rogue AI has come back to bite it
OpenAI logo on Microsoft surface

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

Read more