- Sources: Cloudflare blog, HN discussion
- Summary: Cloudflare reports that its own researchers built a Spectre attack that ran against production Workers over the network and leaked memory at up to 12 bits per second with 99 percent accuracy, under real production noise rather than in a lab. The blog states the work covers research done in 2024 and early 2025, so this is a disclosure of an already-closed result rather than a live finding. Workers runs untrusted tenant code in shared V8 isolates, so the result is an attack on language-level isolation rather than on a hypervisor boundary. Cloudflare states the attack is mitigated in production and that it found no indicators of active exploitation across three years, and it describes further isolation work shipped in response. No affected versions apply to a reader, because Workers is a hosted service and the mitigation shipped on Cloudflare's side. No independent reproduction was located.
- Why it matters: Language-level isolation on a shared process is the security model behind most multi-tenant edge runtimes, and Cloudflare shows it was defeatable remotely under real production noise.
- Follow-up: Track whether other multi-tenant JavaScript isolate runtimes respond with comparable process-level isolation.
send feedback on this story