Researchers disclosed a remote Spectre attack against Cloudflare Workers that leaked a JWT from a co-located Worker in production at up to 12 bits per second, far faster than the 2021 attack. Cloudflare said the issue has been mitigated with improved DyPrIs, the V8 Sandbox, and MPK-based in-process isolation, and reported no signs of active exploitation. #CloudflareWorkers #Spectre #JWT #DyPrIs #V8Sandbox #MPK
Keypoints
- The attack leaked a JWT from a victim Worker in the same production process.
- Leakage reached up to 12 bits per second at 99.16% accuracy.
- The researchers used WebSocket timing and Durable Objects to extend the attack window.
- Cloudflare said it has already deployed mitigations in production.
- The paper argues DyPrIs has fundamental detection limits under I/O-heavy conditions.
Read More: https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html