This sounds very similar to the Time attack from 2013.
https://youtu.be/rTIpFfTp3-w
. I hope they got credited.
They used a timing side channel attack to extract data from a response when compression was enabled and user data is reflected back in a response. This attack can be done inside the browser and abuses how data is segmented when sent over tcp.