Skip to content

SYSTEM Cited by 1 source

V8 Sandbox

The V8 Sandbox is a memory-sandboxing effort in V8 whose goal is to remove raw 64-bit pointers from large parts of the JavaScript heap, so that memory-corruption and speculative-execution primitives that depend on following a raw pointer become much harder to reuse. It is a mitigation within the engine, complementary to process- and hardware-level isolation.

Why it matters for Spectre on Workers

Under V8's pointer compression, most heap objects use 32-bit compressed pointers rather than raw 64-bit machine pointers. But TypedArray was one of the few exceptions: it still stored a raw 64-bit pointer to its backing store. Cloudflare's remote Spectre proof-of-concept against Cloudflare Workers exploited exactly this — a speculative type-confusion gadget followed that raw TypedArray backing-store pointer to turn a leak into an arbitrary-address 64-bit read. At research time the V8 Sandbox was not yet deployed on Workers. (Source: sources/2026-08-19-cloudflare-a-revisit-of-remote-spectre-attacks-on-cloudflare-workers)

By removing those raw pointers, the V8 Sandbox:

  • makes the specific 64-bit speculative type-confusion gadget in this work no longer work (typed-array backing stores no longer expose the same raw pointer structure), and
  • reduces the usefulness of many memory-corruption primitives generally.

Not a complete Spectre mitigation

Cloudflare is explicit that the V8 Sandbox is not a complete Spectre defense: "While the presented 64-bit leak gadget does not work anymore, there might be other Spectre variants or gadgets exploitable to achieve arbitrary out-of-bounds memory accesses." It is therefore one layer of a defense-in-depth stack alongside MPK-based in-process isolation and improved DyPrIs.

Seen in

Last updated · 766 distilled / 2,225 read