0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Opera GX Vulnerability Allowed Automatic Mod Installation and Data Theft (infosecurity-magazine.com)

· 21d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Critical Opera GX flaw: automatic mod installation without user interaction.
  • Attacker CSS injected across all open pages, enabling data exfiltration (e.g., Gmail address).
  • DoS attack possible by forcing mod installation in Incognito mode.
  • Reported in February, patched on May 8, $5,000 bug bounty paid.

"A critical vulnerability in the Opera GX browser allowed malicious websites to automatically install a customization mod and use it to steal data from other visited pages, with no user interaction required. The flaw was patched on May 8, 2026. A researcher published a proof of concept on July 3 and was awarded a $5,000 bug bounty."

Discussion Matrix

0 segments

no comments yet.