A researcher wrote four kilobytes into free space and read back sixty that were not his.
The storage underneath was doing exactly what it had been configured to do.
On 24 September Cloudflare published its account of a cross-tenant data exposure in Containers — the service its own Sandboxes are built on, where a lot of us run agent-generated code.
Flat:
1. Oren Yomtov of Accomplish reported it through HackerOne on 4 September at 15:26 UTC. Cloudflare confirmed the production flaw at 18:45, merged a runtime fix at 21:27 the same day, completed the rollout on 7 September, and cleared the last cached snapshots on 19 September.
2. The numbers, against an isolation model that predicts zero: residual material on 18 of 24 placements and 20 of 22 underlying nodes across four continents, and 2,700 distinct foreign directory inodes identified by checksum. What came back: directory structures, database pages, structurally complete SQLite databases.
3. Before you file this as a container escape: nothing escaped. Thin-provisioned pools with skip_block_zeroing returned deleted 64 KiB blocks to a shared pool without wiping them. A 4 KiB write into ext4 free space claimed a previously used block, the remaining bytes still the last tenant's. Execution isolation held. Storage isolation was never there to hold. The prerequisite was a paid Workers account, not an exploit chain.
4. Cloudflare says remediation "does not require any further action by Cloudflare customers". For security that is true, and six hours from report to merge deserves saying — but if anything personal sat in that sandbox, you are the controller. GDPR Article 33(5) makes you document any personal data breach, its effects and the remedial action, and that documentation has to let a supervisory authority verify your compliance, including your decision not to notify. Article 28(3)(f) obliges your processor to assist, "taking into account the nature of processing and the information available to the processor". Neither Cloudflare's post nor the coverage says individual tenants were told which placements were theirs.
My Monday: list which sandboxes ran on Containers before 7 September and what they persisted. Ask, in writing, under 28(3)(f). Then write the memo either way, because the one you never send is the one Article 33(5) is about.
Isolation you can verify is a boundary. Isolation you are told about is a claim.
Which of yours can you show?
#AgenticAI #GDPR #CloudSecurity #AIGovernance #DevSecOps
AI disclosure: the narration voice, the cover art and the brand ident animation in this video are AI-generated. The script, the claims and the source checks are mine.