logo

Cloudflare CDN flaw leaks user location data, even through secure chat apps

ID: bd412b0a-b8b1-5ae2-a327-8d7875353373

STIX ID: report--bd412b0a-b8b1-5ae2-a327-8d7875353373

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2025-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A researcher found that Cloudflare's CDN caching and a flaw in Cloudflare Workers (and the Teleport tool) can be abused to perform zero-click, coarse-grained geolocation of users by sending images hosted on Cloudflare and enumerating which data centers serve the requests; the technique can localize targets within roughly 50–300 miles and affects apps that auto-download images (like Signal and Discord). Cloudflare patched the Workers abuse, awarded a bounty, and noted users can disable caching, but the researcher demonstrated a VPN-based workaround that still reaches many datacenters and enables the attack in many populated regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.