Opera GX Vulnerability Allowed Automatic Mod Installation and Data Theft (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Critical Opera GX flaw: automatic mod installation without user interaction.
- Attacker CSS injected across all open pages, enabling data exfiltration (e.g., Gmail address).
- DoS attack possible by forcing mod installation in Incognito mode.
- Reported in February, patched on May 8, $5,000 bug bounty paid.
"A critical vulnerability in the Opera GX browser allowed malicious websites to automatically install a customization mod and use it to steal data from other visited pages, with no user interaction required. The flaw was patched on May 8, 2026. A researcher published a proof of concept on July 3 and was awarded a $5,000 bug bounty."
no comments yet.