FROST Attack: Browsers Extract User Behavior via SSD Access Timing (heise.de)
0xBASE INTEL BRIEF
- FROST attack uses SSD access timing as a side channel from the browser.
- Detection rate on macOS: 88.95% for websites, 95.83% for apps.
- Browser vendors have not yet implemented countermeasures.
"Researchers demonstrated the FROST side-channel attack that uses SSD access times from within a browser to infer visited websites and open applications. The attack uses the Origin Private File System API (OPFS) and bypasses the page cache. On macOS, it achieved 88.95% accuracy for websites and 95.83% for apps. Browser vendors have not yet implemented countermeasures."
no comments yet.