Spectre cross-tenant leak in Cloudflare Workers at 12 bps prompts stronger isolation

1 min read
Source: The Hacker News
Spectre cross-tenant leak in Cloudflare Workers at 12 bps prompts stronger isolation
Photo: The Hacker News
TL;DR Summary

Researchers demonstrated a remote Spectre side-channel attack leaking a JWT from a co-located Cloudflare Worker at up to 12 bits/sec (99.16% accuracy) with attacker and victim in separate V8 isolates within the same process; Cloudflare says no customer data was accessed and has mitigated the risk in production by upgrading Dynamic Process Isolation (DyPrIs), adopting the V8 Sandbox, and deploying MPK-based in-process isolation, with no exploitation observed in three years. The study notes DyPrIs detection limitations and urges in-execution signals resilient to IO activity. Tests used Linux AMD EPYC CPUs; leakage scales with load. As of Sept 2025, Cloudflare’s hardening includes stronger DyPrIs, tighter V8 pointer limits, and rotating MPK-backed memory layouts to reduce cross-isolate leakage.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

83%

688116 words

Want the full story? Read the original article

Read on The Hacker News