Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websites you're using
… FROST exploits the Origin Private File System OPFS , a browser API that lets websites create and store files on a user's local disk without prompting for permission. …