A security researcher discovered a flaw in Cloudflare's content delivery network (CDN), which could expose a person's general location by simply sending them an image on platforms like Signal and Discord. While the geo-locating capability of the attack is not precise enough for street-level tracking, it can provide enough data to infer what geographic region a person lives in and monitor their movements. Daniel's finding is particularly concerning for people who are highly concerned about their privacy, like journalists, activists, dissidents, and even cybercriminals. However, for law enforcement, this flaw could be a boon to investigations, allowing them to learn more about the country or state where a suspect may be located. Three months ago, a security researcher named Daniel discovered that Cloudflare caches media resources at the data center nearest to the user to improve load times. "3 months ago, I discovered a unique 0-click deanonymization attack that allows an attacker to grab the location of any target within a 250 mile radius," explained Daniel. "With a vulnerable app installed on a target's phone (or as a background application on their laptop), an attacker can send a malicious payload and deanonymize you within seconds--and you wouldn't even know. To conduct the information-disclosure attack, the researcher would send a message to someone with a unique image, whether that be a screenshot or even a profile avatar, hosted on Cloudflare's CDN. Next, he leveraged a...
Cloudflare CDN flaw leaks user location data, even through secure chat apps
BleepingComputer
·Bill Toulas
·Published Jan 22, 2025
·Updated
Affected Software
5 affected components
Cloudflare CDN
Cloudflare Workers
Signal App
Discord App
Cloudflare content delivery network
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in Cloudflare's CDN that can leak user location data through image-sharing on secure chat apps.
2
What security implications are discussed in the article?
The flaw allows users' general location data to be exposed when images are sent via platforms like Signal and Discord.
3
What products or software are affected by the Cloudflare CDN flaw?
The affected products include Cloudflare CDN, Cloudflare Workers, Signal App, and Discord App.
4
How does the vulnerability impact user privacy?
The vulnerability compromises user privacy by exposing their location data even when using supposedly secure messaging apps.
5
What should users of affected platforms do in response to this issue?
Users should stay informed about updates from Cloudflare and the affected apps to mitigate potential privacy risks.