Updated
Updated · The Cloudflare Blog · Aug 20
Cloudflare Mitigates 12-Bit/Second Spectre Leak on Workers After 99%-Accurate Production Test
Updated
Updated · The Cloudflare Blog · Aug 20

Cloudflare Mitigates 12-Bit/Second Spectre Leak on Workers After 99%-Accurate Production Test

3 articles · Updated · The Cloudflare Blog · Aug 20

Summary

  • Cloudflare said its researchers reproduced a remote Spectre attack on Workers that leaked cross-isolate data at up to 12 bit/s with more than 99% accuracy in production.
  • The test exposed a weakness in Dynamic Process Isolation: long-lived Durable Object and WebSocket-heavy workloads could evade post-execution isolation, while remote timing traffic diluted DyPrIs detection signals.
  • Cloudflare said the attack is already mitigated in production after upgrading DyPrIs, adding the V8 Sandbox, and deploying Memory Protection Keys-based in-process isolation in September 2025.
  • The company said it found no signs of active exploitation over the past three years, and the published paper covers research conducted in 2024 and early 2025.
  • The findings underscore that speculative-execution risks remain practical even in heavily restricted serverless environments, pushing defenses toward stronger hardware isolation and behavior-based detection.

Insights

Could seemingly harmless web traffic be secretly masking data-stealing side-channel attacks in your cloud environment?
Are high-speed cloud platforms sacrificing critical security by leaving sensitive tokens vulnerable to hardware flaws?