Cloudflare’s Privacy Flaw: How an Innocent Image Could Reveal Your Whereabouts!
Daniel discovered a flaw in Cloudflare’s CDN that could track a person’s general location by sending an image on apps like Signal and Discord. This zero-click attack is a privacy nightmare for journalists and activists, but a detective’s dream. Cloudflare patched the bug, but Daniel found a way to continue the geo-locating attacks.

Hot Take:
Who knew that sending your friend a harmless meme could turn into an accidental game of ‘Where in the World is Carmen Sandiego?’ Thanks to Cloudflare, your location could be up for grabs with just a single image. Maybe it’s time to go retro and send postcards instead?
Key Points:
- A flaw in Cloudflare’s CDN could expose a user’s general location through image sharing.
- The attack leverages a bug in Cloudflare Workers to force requests through specific data centers.
- The flaw allows for zero-click tracking, with accuracy ranging from 50 to 300 miles.
- The issue is particularly concerning for privacy-sensitive individuals like journalists and activists.
- Cloudflare patched the bug, but the attack is still feasible using alternative methods.
Already a member? Log in here