A revisit of remote Spectre attacks on Cloudflare Workers
ID: db1616b7-1db3-52e5-88b7-68fed9d28ab9
STIX ID: report--db1616b7-1db3-52e5-88b7-68fed9d28ab9
Feed Name: Cloudflare Blog
Cloudflare publishes a technical paper describing a production proof-of-concept remote Spectre attack against Cloudflare Workers that can leak cross-isolate memory (demonstrated bitwise exfiltration of up to 12 bits/s at >99% accuracy). The report details attack primitives (Spectre gadgets, PLRU amplification, noisy remote timers, co-location via Durable Objects), why their prior DyPrIs detection was bypassed, and the mitigations they deployed (V8 sandbox hardening, in-process MPK isolation, and DyPrIs improvements); they report no indicators of active exploitation over the last three years.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
