cloudflare (1)

Cloudflare CDN flaw leaks user location data, even through secure chat apps

Teilen:

A security researcher discovered a flaw in Cloudflare’s content delivery network (CDN), which could expose a person’s general location by simply sending them an image on platforms like Signal and Discord.

While the geo-locating capability of the attack is not precise enough for street-level tracking, it can provide enough data to infer what geographic region a person lives in and monitor their movements.

Daniel’s finding is particularly concerning for people who are highly concerned about their privacy, like journalists, activists, dissidents, and even cybercriminals.

However, for law enforcement, this flaw could be a boon to investigations, allowing them to learn more about the country or state where a suspect may be located.

Stealthy 0-click tracking

Three months ago, a security researcher named Daniel discovered that Cloudflare caches media resources at the data center nearest to the user to improve load times.

“3 months ago, I discovered a unique 0-click deanonymization attack that allows an attacker to grab the location of any target within a 250 mile radius,” explained Daniel.

“With a vulnerable app installed on a target’s phone (or as a background application on their laptop), an attacker can send a malicious payload and deanonymize you within seconds–and you wouldn’t even know.

To conduct the information-disclosure attack, the researcher would send a message to someone with a unique image, whether that be a screenshot or even a profile avatar, hosted on Cloudflare’s CDN.

Next, he leveraged a bug in Cloudflare Workers that allows forcing requests through specific data centers using a custom tool called Cloudflare Teleport.

This arbitrary routing is normally disallowed by Cloudflare’s default security restrictions, which dictate that each request is routed from the nearest data center.

By enumerating cached responses from different Cloudflare data centers for the sent image, the researcher could map the general location of users based on the CDN returning the closest airport code near their data center.

Calculating response times
Calculating response times
Source: hackermondev | GitHub

Additionally, since many apps automatically download images for push notifications, including Signal and Discord, an attacker can track a target without user interaction, making this a zero-click attack.

The tracking accuracy ranges between 50 and 300 miles, depending on the region and how many Cloudflare datacenters are nearby. Precision around major cities should be better than in rural or less populated areas.

While experimenting with geo-locating Discord’s CTO, Stanislav Vishnevskiy, the researcher found that Cloudflare uses anycast routing with multiple nearby data centers handling a request for better load balancing, allowing even better accuracy.

Locating the target
Locating the target
Source: hackermondev | GitHub

Response from affected platforms

As first reported by 404 Media, the researcher disclosed his findings to Cloudflare, Signal, and Discord, and the former marked it as resolved and awarded him a $200 bounty.

Daniel confirmed that the Workers bug was patched, but by reprogramming Teleport to use a VPN to test different CDN locations, the geo-locating attacks are still possible, if a bit more cumbersome now.

“I chose a VPN provider with over 3,000 servers located in various locations across 31 different countries worldwide,” explains the researcher in his writeup.

“Using this new method, I’m able to reach about 54% of all Cloudflare datacenters again. While this doesn’t sound like a lot, this covers most places in the world with significant population.”

Responding to a subsequent request, Cloudflare told the researcher that it is ultimately the users’ responsibility to disable caching.

Discord rejected the report as a Cloudflare issue, as did Signal, noting that it’s outside their mission’s scope to implement network-layer anonymity features.

BleepingComputer has reached out to Signal, Discord, and Cloudflare for a comment on the researcher’s findings.

A Cloudflare spokesperson told us the following:

“This was first disclosed in December 2024 through our bug bounty program, investigated and immediately resolved. The ability to make requests to specific data centres via the “Cloudflare Teleport” project on GitHub was quickly addressed – as the security researcher mentions in their disclosure. We believe bug bounties are a vital part of every security team’s toolbox, and continue to encourage third parties and researchers to continue to report this type of activity for review by our team.” – Cloudflare spokesperson

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:27 am, Mai 9, 2025
Wetter-Symbol 14°C
L: 12° | H: 15°
klarer Himmel
Luftfeuchtigkeit: 69 %
Druck: 1021 mb
Wind: 8 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 5%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:17 am
Sonnenuntergang: 8:35 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 15°°C 0 mm 0% 12 mph 63 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 12 mph 86 % 1021 mb 0 mm/h
So. Mai 11 10:00 pm
Wetter-Symbol
11° | 23°°C 0.94 mm 94% 12 mph 86 % 1015 mb 0 mm/h
Mo. Mai 12 10:00 pm
Wetter-Symbol
12° | 21°°C 0.97 mm 97% 11 mph 95 % 1016 mb 0 mm/h
Di. Mai 13 10:00 pm
Wetter-Symbol
13° | 21°°C 0.46 mm 46% 11 mph 77 % 1022 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
15° | 16°°C 0 mm 0% 12 mph 59 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 11 mph 45 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 9 mph 40 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 8 mph 63 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 6 mph 74 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 4 mph 86 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 79 % 1020 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 8 mph 47 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,562.70
3.23%
Ethereum(ETH)
€2,087.05
20.99%
Fesseln(USDT)
€0.89
-0.02%
XRP(XRP)
€2.10
6.88%
Solana(SOL)
€147.91
8.67%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.182043
11.64%
Shiba Inu(SHIB)
€0.000013
10.96%
Pepe(PEPE)
€0.000012
42.03%
Peanut das Eichhörnchen(PNUT)
€0.239374
57.75%
Nach oben scrollen