Breaking
March 13, 2025

Cloudflare CDN flaw could expose user location simply by sending an image | usagoldmines.com


  • A security researcher discovered a way to abuse how Cloudflare cached certain images
  • The method could allow outsiders to partially de-anonymize people
  • The bug was quickly fixed, Cloudflare assures users

Experts have found a way to partially de-anonymize a person and find out their general location by simply sending them a picture on certain messaging platforms.

This is according to a 15-year-old cybersecurity researcher named Daniel, who recently found a vulnerability in Cloudflare’s content delivery network (CDN).

In theory, the vulnerability is simple. Cloudflare wants people to receive their messages, and multimedia, as quickly as possible. For that reason, images that are being sent go through a data center that’s nearest to the recipient. If the attacker could learn which data center that is, they could get a solid picture of their target’s location.

A 200-mile radius

“One of Cloudflare’s most used feature is Caching. Cloudflare’s Cache stores copies of frequently accessed content (such as images, videos, or webpages) in its datacenters, reducing server load and improving website performance,” Daniel explained.

“When your device sends a request for a resource that can be cached, Cloudflare retrieves the resource from its local datacenter storage, if available. Otherwise, it fetches the resource from the origin server, caches it locally, and then returns it. By default, some file extensions are automatically cached but site operators can also configure new cache rules.”

“If you live in a developed country, there’s a good chance the nearest datacenter to you is less than 200 miles from you.” Since some apps, like Signal, or Discord, show the image’s thumbnail in the notification, it makes this a zero-click vulnerability.

Daniel further explained Cloudflare returns information about a request’s cache status in the HTTP response, including the airport code for the closest airport to the data center.

Next, he used a bug in Cloudflare Workers, and used a tool called Cloudflare Teleport, forcing requests through a specific data center.

A few months after the bug was discovered, Cloudflare patched it up, telling BleepingComputer it was disclosed in December 2024, and “immediately resolved.”

“The ability to make requests to specific data centres via the “Cloudflare Teleport” project on GitHub was quickly addressed – as the security researcher mentions in their disclosure. We believe bug bounties are a vital part of every security team’s toolbox, and continue to encourage third parties and researchers to continue to report this type of activity for review by our team.”

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Best Chromebooks 2025: Best overall, best battery life, and more | usagoldmines.com

Best monitors 2025: Gaming, 4K, HDR, and more | usagoldmines.com

Why You Might Want to Avoid the Latest Chromecast Update Jake Peterson | usagoldmines.com

Whoop Can Now Estimate Your VO2 Max Beth Skwarecki | usagoldmines.com

OpenAI Calls on U.S. Government to Let It Freely Use Copyrighted Material for AI Training Juli Clove...

AI server designed for Chinese military use wins major global design award in Europe waynewilliams@o...

‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web...

The FCC is creating a security council to bolster US defenses against cyberattacks | usagoldmines.c...

Toyota's self-charging concept EV could help you tackle the daily commute on solar power alone | us...

Google has a fix for your broken Chromecast V2 unless you factory reset Ryan Whitwam | usagoldmines....

Popular program to promote women becoming aerospace engineers is at risk Eric Berger | usagoldmines....

Fortnite is coming to Snapdragon PCs: ‘We’re all in on PC gaming’ | usagoldmines.com

Android 16 Beta 3 Available for Pixel Devices Kellen | usagoldmines.com

Google Pushes Initial Fix for Chromecast 2nd Gen and Audio Outage Kellen | usagoldmines.com

A New 'Add to Calendar' Button Is Coming to Gmail Khamosh Pathak | usagoldmines.com

This 2020 M1 MacBook Air Is Over $500 Off Right Now Pradershika Sharma | usagoldmines.com

Mac Mini vs. Mac Studio Buyer's Guide: 20+ Differences Compared Hartley Charlton | usagoldmines.com

Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in ...

Microsoft uncovers sleuthy new XCSSET MacOS malware campaign | usagoldmines.com

Have we accidentally bred some dogs for obesity? Jacek Krywko | usagoldmines.com

Meta plans to test and tinker with X’s community notes algorithm Ashley Belanger | usagoldmines.com

Windows 11 bug with Nvidia GPUs prevents apps from launching | usagoldmines.com

Eufy FamiLock S3 Max review: Lock, stock, and onboard video | usagoldmines.com

Gemini Connects to More Apps, Like Google Tasks and Photos Tim | usagoldmines.com

Galaxy S23 Family Gets One UI 7 Beta Access Tim | usagoldmines.com

T-Mobile Continues Raising Prices on Older Plans, Up to $5 Per Line Kellen | usagoldmines.com

Google Has Dropped the Paywall for These Gemini Features Khamosh Pathak | usagoldmines.com

You Need Update Firefox Before Friday Jake Peterson | usagoldmines.com

Kuo: Apple Knows Apple Intelligence is 'Underwhelming' and Won't Drive iPhone Upgrades Juli Clover |...

Get ready for a bounty of PC games on June 8, as the PC Gaming show is back | usagoldmines.com

I cloned my voice in seconds using a free AI app, and we really need to talk about speech synthesis ...

Google’s Gemini AI can now see your search history Ryan Whitwam | usagoldmines.com

Best ultrawide monitors 2025: Picks for gaming, budget, 5K, premium, and more | usagoldmines.com

Best VPN for streaming Netflix 2025: Watch from wherever you are | usagoldmines.com

I’m trying to replace my Apple TV with a home theater PC | usagoldmines.com

Kensington’s new Expert Mouse trackball looks great, but availability is uncertain | usagoldmines.c...

Slip this tracker in your wallet and never lose it again, now 30% off | usagoldmines.com

Anker’s fast-charging USB wall plug for 3 devices is 37% off right now | usagoldmines.com

Google Play Games on PC Gets Major Upgrades, More Games, New Play Points Bonuses Kellen | usagoldmin...

Google’s Gemini Gets “Personalization” Using Your Search History If You Are Cool With That Kellen | ...

My Favorite Method for Scrambling Eggs Isn't What I Predicted Allie Chanthorn Reinmann | usagoldmine...

You Can Use the Windows App to Acess Your PC Remotely or in the Cloud David Nield | usagoldmines.com

Netflix might be renewing The Perfect Couple and Beauty in Black for season 2, but I don’t get why w...

The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000 s...

I made an AI version of Bilbo Baggins using Goggle Gemini for free, and shared a pipe with him outsi...

Gemini Deep Research just got even smarter and it’s now free for everyone to try - here's why you sh...

Google just gave Gemini a superpower by allowing it to access your Search history - here's why I'm e...

Meta warns of worrying security flaw hitting open source type software | usagoldmines.com

Ubisoft shareholder accuses publisher of 'misleading investors', plans protest outside Paris HQ | u...

Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the r...

Biometrics add another layer of security to passwordless authentication | usagoldmines.com

Microsoft’s new AI “Copilot for Gaming” struggles to justify its existence Kyle Orland | usagoldmine...

AI coding assistant refuses to write code, tells user to learn programming instead Benj Edwards | us...

Google is bringing every Android game to Windows in big gaming update Ryan Whitwam | usagoldmines.co...

OpenAI urges Trump: Either settle AI copyright debate or lose AI race to China Ashley Belanger | usa...

Amazon Spring Sale 2025: What to expect and best early deals | usagoldmines.com

HP’s latest firmware update breaks printers using HP’s own toner | usagoldmines.com

Corsair Platform:4 review: A modular desk with powerful features | usagoldmines.com

Wow! Samsung’s 34-inch 1440p OLED ultrawide monitor is $520 off | usagoldmines.com

You Can Get a Lifetime Subscription to Babbel on Sale for $129 Right Now Pradershika Sharma | usagol...

Amazon Takes Up to $450 Off M4 MacBook Pro, Available From $1,399 Mitchel Broussard | usagoldmines.c...

Apple Music Classical Now Available on the Web Joe Rossignol | usagoldmines.com

Microsoft warns about a new phishing campaign impersonating Booking.com | usagoldmines.com

Latest Dune Awakening trailer provides a deeper look at open-world exploration on the planet Arrakis...

Microsoft confirms Copilot can be tested by Xbox Insiders next month and shares new details about ho...

'We're optimists': AI enthusiasts Joe and Anthony Russo defend its use in movies and TV shows, but a...

The new Apple MacBook Air M4 has a weird quirk with its performance cores - but it's nothing to worr...

40% of IT leaders scared to admit mistakes due to workplace culture of fear | usagoldmines.com

The EPA is scrapping fuel economy regs, claiming it will bring back US jobs Jonathan M. Gitlin | usa...

Trump’s EPA clearly shows it doesn’t understand the assignment Marianne Lavelle and Phil McKenna, In...

Epic Games is addressing one of Windows-on-Arm’s last big app compatibility gaps Andrew Cunningham |...

5 creative ways to use a PC video capture card | usagoldmines.com

Printers are spitting out nonsense after a borked Windows update | usagoldmines.com

You Should Spring Clean Your Finances Too Meredith Dietz | usagoldmines.com

This Highly Rated 75-Inch 4K ULED TV Is Under $500 Right Now Pradershika Sharma | usagoldmines.com

Amtrak's Redesigned iPhone App Offers Easier Access to Train Status, Tickets, and More Joe Rossignol...

Emily in Paris season 5: everything we know so far about the hit Netflix show’s return | usagoldmin...

Thousands of iOS apps found to expose user data and leak Stripe keys | usagoldmines.com

Sonos reportedly cancels its streaming video player, but I hope it resurrects one part of it, becaus...

Windows survival skills: 8 things every PC user should know how to do | usagoldmines.com

Acer Chromebook Plus Spin 514 review: This 2-in-1 nearly nails it | usagoldmines.com

How ChatGPT coached me to email greatness | usagoldmines.com

My Favorite Recipes to Get the Most Out of Your Dutch Oven Allie Chanthorn Reinmann | usagoldmines.c...

What You Actually Need to Know About Measles and the MMR Vaccine Beth Skwarecki | usagoldmines.com

Apple Announced Swift Assist at WWDC 2024... So Where Is It? Tim Hardwick | usagoldmines.com

Invincible season 3 ending explained: is [spoiler] dead, Damien Darkblood end credits scene, will th...

Intel reveals its new CEO | usagoldmines.com

AMD's most powerful processor ever actually runs better on Windows 10 than Windows 11 alekshamclough...

Hacked Tata Technologies data leaked by ransomware gang | usagoldmines.com

No, your printer isn't possessed: a Windows 11 23H2 bug could be making it print random characters w...

Actually, yes, Assassin's Creed Shadows will be playable on Steam Deck at launch, Ubisoft confirms ...

Why effective cybersecurity is a team effort | usagoldmines.com

The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade | usagoldm...

The Taylor Sheridan supremacy lives on at Paramount+ as Landman gets renewed for season 2 grace.morr...

Samsung tipped to unveil first-ever bone-conduction headphones at Galaxy Z Fold 7 event stephen.warw...

The newly revealed Inzoi system requirements are enough to make me go back to The Sims 4 dash.wood@f...

iOS 18.4 will give your iPhone a much-needed maps upgrade – but only if you're in the EU alexblake.t...

The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign | usagold...

This Redditor installed a game engine on their smartwatch, and now it runs Doom, Quake, and Half-Lif...

Today’s Steam Spring Sale features my absolute favorite game of all time - here's when the sale star...

Leave a Reply