importantSYS.SOURCE: The Hacker News• 2026-08-20T00:32:40+05:30
Cloudflare Workers Spectre Attack Leaks JWT via Co-Located Worker at 12 Bits/Second
A remote Spectre attack on Cloudflare Workers demonstrated leaking a JWT from a co-located worker at 12 bits/second, 360x faster than a 2021 attack, highlighting limitations in Dynamic Process Isolation (DyPrIs) despite subsequent mitigations like V8 Sandbox and MPK-based isolation.
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.
The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,
*** END OF TRANSMISSION ***