Cloudflare Mitigates 12-Bit/Second Spectre Leak on Workers After 99%-Accurate Production Test
Updated
Updated · The Cloudflare Blog · Aug 20
Cloudflare Mitigates 12-Bit/Second Spectre Leak on Workers After 99%-Accurate Production Test
3 articles · Updated · The Cloudflare Blog · Aug 20
Summary
Cloudflare said its researchers reproduced a remote Spectre attack on Workers that leaked cross-isolate data at up to 12 bit/s with more than 99% accuracy in production.
The test exposed a weakness in Dynamic Process Isolation: long-lived Durable Object and WebSocket-heavy workloads could evade post-execution isolation, while remote timing traffic diluted DyPrIs detection signals.
Cloudflare said the attack is already mitigated in production after upgrading DyPrIs, adding the V8 Sandbox, and deploying Memory Protection Keys-based in-process isolation in September 2025.
The company said it found no signs of active exploitation over the past three years, and the published paper covers research conducted in 2024 and early 2025.
The findings underscore that speculative-execution risks remain practical even in heavily restricted serverless environments, pushing defenses toward stronger hardware isolation and behavior-based detection.