A security researcher has discovered a flaw in Cloudflare's content delivery network (CDN) that could expose a person's location data by simply sending them an image on platforms like Signal and Discord.
See also: Cloudflare blocked DDoS attack that peaked at 5.6 Tbps

While the defect's geo-localization capability is not accurate enough for street-level monitoring, it can provide enough data to infer what geographic area a person lives in and track their movements.
The finding is particularly concerning for people who are particularly concerned about their privacy, such as journalists, activists, dissidents, and even cybercriminals . However, for law enforcement, this flaw could be a boon to investigations, allowing them to learn more about the country or state where a suspect may be located.
Three months ago, a security researcher named Daniel discovered that Cloudflare was secretly storing media resources in the data center closest to the user to improve loading times.
“3 months ago, I discovered a unique zero-click deanonymization attack that allows an attacker to pinpoint the location of any target within a 250-mile radius,” Daniel explained.
To carry out the information disclosure attack, the researcher sent a message to someone with a unique image, whether it was a screenshot or even a profile avatar, hosted on Cloudflare's CDN. He then exploited a flaw in Cloudflare Workers that allows requests to be forced through specific data centers using a custom tool called Cloudflare Teleport.
See also: UAC-0125 hackers abuse Cloudflare Workers to distribute malware

This arbitrary routing is typically not allowed by Cloudflare's default security restrictions, which dictate that every request is routed from the nearest data center.
By listing cached responses from different Cloudflare data centers for the uploaded image, the researcher could map the general location of users based on the CDN that returns the nearest airport code near data center . Additionally, since many apps automatically download images for push notifications, including Signal and Discord, an attacker can track a target without user interaction, making the attack a zero-click attack.
The tracking accuracy that the flaw allows ranges between 50 and 300 miles, depending on the area and how many Cloudflare data centers are nearby. Accuracy around major cities should be better than in rural or less populated areas.
While experimenting with geolocation for Discord's CTO, researcher Stanislav Vishnevskiy, he found that Cloudflare uses anycast with multiple nearby data centers handling a request for better load balancing, allowing for even better accuracy.
See also: Cloudflare's developer domains are being abused by hackers
Cloudflare is a widely used platform that provides content delivery network (CDN) services, DDoS , and internet security for websites worldwide. However, like any complex technology, it is not immune to vulnerabilities. One notable flaw that has been observed in the past is “Cloudbleed,” which was introduced in 2017. This vulnerability arose due to an error in Cloudflare’s code, causing the leakage of sensitive data such as authentication tokens, cookies, and passwords from various websites using the service. Although the flaw was quickly addressed by Cloudflare after its discovery, it emphasized the importance of rigorous code testing and security controls to safeguard critical infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
