logo

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

ID: f4a0e5b7-a825-5419-90f3-816e7e5a3f4c

STIX ID: report--f4a0e5b7-a825-5419-90f3-816e7e5a3f4c

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: [email protected] (The Hacker News)

...
...

Researchers demonstrated a remote Spectre-based side‑channel attack against Cloudflare Workers that can exfiltrate JWTs from co‑located isolates (up to ~12 bits/sec in tests). The paper details how long‑lived Durable Objects and WebSocket timing enable the attack, shows diminished detection under certain I/O patterns, and contrasts the new results with a prior 2021 proof; Cloudflare has deployed mitigations (improved DyPrIs, V8 Sandbox, MPK-based isolation) and reported no signs of active exploitation in production.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.