Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cybersecurity researchers have demonstrated a remote Spectre-style attack against Cloudflare Workers that could leak sensitive data like JWTs from co-located processes. Cloudflare has since mitigated the vulnerability by enhancing its process isolation and sandbox protections.
Why it matters
This highlights the ongoing security challenges in multi-tenant cloud environments where performance optimizations like shared memory can create side-channel vulnerabilities.
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.
The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers, with the JWT intentionally placed in the victim's memory. The research paper stated that no customer data was accessed.
Cloudflare said the attack has already been mitigated in production after it improved Dynamic Process Isolation (DyPrIs), integrated the V8 Sandbox , and deployed Memory Protection Keys (MPK)-based in-process isolation, adding that it found no indicators of active exploitation over the last three years.
"We demonstrate that the production implementation of DyPrIs was insufficient," the researchers said in the paper .
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in