Cloudflare Workers Spectre Attack Leaks JWT at 12 Bits/s
Discover how a remote cloudflare workers spectre attack leaked JWTs at 12 bits/second and how the new V8 Sandbox mitigates this vulnerability.
Cybersecurity researchers from TU Graz have disclosed a highly sophisticated Remote-Timer-as-a-Service side-channel execution flaw against serverless edge environments. In a controlled production test, this cloudflare workers spectre attack successfully leaked a JSON Web Token (JWT) from a co-located Worker at an astonishing rate of 12 bits per second (at 99.16% accuracy)โnearly 360 times faster than similar attacks demonstrated in 2021.
Cloudflare mitigated the issue by heavily upgrading its Dynamic Process Isolation (DyPrIs), integrating Google's V8 Sandbox, and implementing hardware-enforced Memory Protection Keys (MPK) to physically isolate Worker heaps.
๐ Read the Full Technical Breakdown and Diagrams on CyberUpdates365
Top comments (0)