A 15-year-old researcher discovered a 0-click deanonymization attack that can pinpoint a user's location within a 250-mile radius by exploiting Cloudflare's caching feature. The attack works by sending a malicious payload to a vulnerable app, such as Signal or Discord, and then using Cloudflare's cache geolocation method to identify the user's location. The researcher demonstrated the attack on Signal and Discord, showing how it can be used to track users without their knowledge or interaction. The attack has significant implications for users who rely on these apps for secure communication.