
Spectre cross-tenant leak in Cloudflare Workers at 12 bps prompts stronger isolation
Researchers demonstrated a remote Spectre side-channel attack leaking a JWT from a co-located Cloudflare Worker at up to 12 bits/sec (99.16% accuracy) with attacker and victim in separate V8 isolates within the same process; Cloudflare says no customer data was accessed and has mitigated the risk in production by upgrading Dynamic Process Isolation (DyPrIs), adopting the V8 Sandbox, and deploying MPK-based in-process isolation, with no exploitation observed in three years. The study notes DyPrIs detection limitations and urges in-execution signals resilient to IO activity. Tests used Linux AMD EPYC CPUs; leakage scales with load. As of Sept 2025, Cloudflare’s hardening includes stronger DyPrIs, tighter V8 pointer limits, and rotating MPK-backed memory layouts to reduce cross-isolate leakage.







