Breaking
Live threat feed August 18, 2026 | 11:11 UTC
6433 CVEs This Month
10 Actively Exploited
0 Ransomware Activity
34 Breaches YTD
Threat Investigation Portal
Investigate an IOC in the live graph workspace.
Investigate IOC
Vulnerabilities

Opera GX Vulnerability Allowed Malicious Sites to Auto-Install Data-Stealing Browser Add-ons

Opera GX Vulnerability Allowed Malicious Sites to Auto-Install Data-Stealing Browser Add-ons

Security researchers discovered a vulnerability in Opera GX that could allow a malicious website to automatically install a browser extension without user interaction. This extension could then access and extract specific data from web pages visited by the user, as demonstrated by reconstructing a full Gmail address from a signed-in user in a proof of concept. Opera has fixed the issue and reported no evidence of exploitation.

What happened

Researchers identified a security flaw in Opera GX, a gaming-focused web browser variant, that permitted malicious websites to silently install browser add-ons. These add-ons were then capable of extracting targeted data from pages visited by the user. The exploit required no clicks or additional user actions, enabling stealthy data harvesting.

In a proof-of-concept demonstration, the researchers successfully reconstructed a signed-in user's complete Gmail address following a single visit to a malicious website. This illustrated the degree to which sensitive information could be obtained through the flaw. Opera has since released a patch to address the vulnerability.

Why it matters

This vulnerability highlights a significant risk where browsers may allow unauthorized extensions to be added without explicit user consent, potentially compromising user privacy. The ability to harvest sensitive data such as email addresses from visited pages could be leveraged for targeted attacks, phishing, or identity theft.

Given the increasing use of browser extensions and their deep access to web content, such automatic installations pose a substantial security threat. Timely addressing these weaknesses is critical to maintaining user trust and safeguarding personal information in browsers targeted at specific user groups, like gamers in this case.

What security teams should do

Security teams and end users should ensure that their Opera GX installations are updated to the latest patched version that addresses this issue. Regular review of installed browser extensions is advisable to detect any unauthorized additions.

Monitoring browser activity for unusual behavior and following vendor advisories on security patches and configurations can help mitigate risks from similar vulnerabilities. Organizations deploying Opera GX should educate users about cautious browsing and extension management.

Key technical details

The flaw involved the silent installation of a signed browser add-on by a visiting malicious website without requiring any user interaction such as clicking. Once installed, the extension leveraged its privileges to extract specific data from web pages the user visited.

The proof of concept used this capability to rebuild the full Gmail address of a signed-in user, demonstrating that the add-on could access sensitive content within the browser session. Opera has addressed the issue by patching the extension installation mechanism to prevent unauthorized automatic add-on installations.

Affected organizations/products

Opera GX browser users were affected by this vulnerability. Opera has released a patch but reported no evidence that the flaw was exploited in the wild prior to the fix.

Source attribution

https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html

Thirumala Rao Padilam
Written by
Thirumala Rao Padilam
error: Content is protected !!