Cloudflare published research detailing remote Spectre attacks against Cloudflare Workers in production and deployed mitigations including Memory Protection Keys, V8 Sandbox, and improved Dynamic Process Isolation.
Aug 18, 2026
13d agoKey Details
- Demonstrated remote Spectre proof-of-concept leaking up to 12 bit/s with 99% accuracy in production workloads using PLRU amplification and Durable Objects WebSocket keep-alives.
- Integrated V8 Sandbox and deployed in-process isolation using Memory Protection Keys (MPK) in September 2025 to restrict cross-isolate memory access.
- Improved Dynamic Process Isolation (DyPrIs) to handle long-lived executions and I/O-heavy workloads as first-class security cases.
- Co-authored research paper with researchers from the University of Edinburgh covering work from 2024 and early 2025.