FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·CriticalBreaking

New browser attack tracks SSDs

A digital illustration of a computer SSD with a glowing fingerprint on it, symbolizing user tracking through hardware analysis.

TL;DR: A new side-channel attack called FROST allows websites to track users across different sites without cookies. It exploits modern browser APIs to measure subtle interactions with a computer's solid-state drive (SSD), creating a unique fingerprint to identify visitors and monitor their browsing activity.

By Neeraj Dhiman·3h ago·1 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
Critical
Published
3h ago
Source
Ars Technica

Full summary

A new browser-based attack called FROST can track users across websites by analyzing the activity of their solid-state drive (SSD).

Researchers have detailed a new side-channel attack called FROST that enables cross-site user tracking by analyzing a computer's solid-state drive (SSD). The technique uses standard browser APIs to run computational tasks and precisely measure the subtle performance variations of the underlying SSD. These timing differences create a unique hardware fingerprint, allowing a website to identify and follow a user across different domains without relying on cookies or other common identifiers. This method is effective because different SSD models and even individual drives exhibit distinct response patterns that can be detected and used as a persistent identifier.

The FROST attack represents a significant new threat to user privacy because it can bypass conventional anti-tracking protections like cookie blockers and private browsing modes. For developers, security teams, and CTOs, it highlights how seemingly benign browser features designed for performance can be repurposed for surveillance. The attack requires no special permissions and can run silently in the background of a webpage. This discovery puts pressure on browser vendors to re-evaluate the security of low-level APIs, as they can expose hardware-level information that was previously considered inaccessible, creating a new and challenging front in the battle for online privacy.

Why it matters

This attack demonstrates a new vector for user tracking that bypasses traditional privacy protections like cookie blockers. It shows how standard browser APIs can be exploited to extract unique hardware fingerprints, creating a new challenge for web security and user privacy.

Business impact

Businesses handling sensitive user data must be aware of this emerging threat class. It could undermine user trust and create compliance risks if third-party scripts on a company's website use such techniques. Security teams need to consider browser-based hardware fingerprinting in their threat models.

Tags

#Privacy#security#side-channel attack#browser#fingerprinting#ssd

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Primary source: Ars Technica

Part of our research on

  • Critical CVEs of 2026 →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube