FROST: Malicious Website Exploitation of SSD/NVMe Timing Side-Channels in Google Chrome, Mozilla Firefox, and Brave
The FROST attack is a hardware-level timing side-channel vulnerability that allows malicious websites to conduct high-fidelity user surveillance by analyzing I/O latency signals from NVMe SSD controllers. By leveraging high-resolution browser APIs to measure micro-delays in disk read/write operations, an attacker can fingerprint the specific I/O signatures generated by local applications and operating system processes. This exploitation occurs via a passive "drive-by" mechanism, requiring no user interaction or privileged system access, and fundamentally circumvents existing browser security boundaries, including the Same-Origin Policy (SOP), sandboxing, and privacy-preserving modes such as Incognito or cookie-blocking extensions. Because the signal is derived from shared physical hardware rather than software-defined identifiers, the attack remains invisible to traditional endpoint detection and response (EDR) tools and browser-based privacy mitigations.