Ethical Hacking News
Opera GX's silent data theft vulnerability has left many users worried about their online safety. The latest discovery highlights the need for users to be vigilant about online security and take steps to protect themselves.
The Opera GX browser has a vulnerability that allows malicious websites to silently install browser add-ons and steal sensitive data from visited pages without user interaction. The vulnerability was identified in the way Opera GX handles extensions, allowing attackers to access data without warning or confirmation from users. A proof-of-concept attack demonstrated how malicious sites can use this vulnerability to steal sensitive information such as Gmail addresses. Opera has patched the flaw and released version 130.0.5847.89 as the fix, but users should be aware of this vulnerability and take steps to protect themselves.
The world of cybersecurity is constantly evolving, and the latest discovery has left many users worried about their online safety. In a shocking revelation, researchers have found a vulnerability in the gaming-focused version of the Opera browser, Opera GX, that allows malicious websites to silently install browser add-ons and steal sensitive data from visited pages without any user interaction.
The discovery was made by a team of experts who identified a flaw in the way Opera GX handles extensions. According to the researchers, this auto-install behavior can be exploited by malicious sites to install malicious mods that can siphon sensitive information from unsuspecting users. This vulnerability is particularly concerning because it allows attackers to access data without any warning or confirmation from the user.
The researchers conducted a proof-of-concept attack using Opera GX version 130.0.5847.89, which patched the flaw. They demonstrated how malicious websites can use this vulnerability to steal sensitive information, such as Gmail addresses, by installing a mod that leverages attribute selectors and CSS injections to extract data from visited pages.
The researchers also noted that this vulnerability is not new, as it was identified back in 2023 by another researcher named Renwa. However, Opera's bug bounty team rated the issue P1, its top severity, and paid the maximum $5,000 award for a critical bug, indicating that the company takes this threat seriously.
In an effort to address this vulnerability, Opera has patched the flaw and released version 130.0.5847.89 as the fix. Users who are currently running a current build can confirm their version by accessing opera://about. This patch should provide users with some level of protection against malicious sites attempting to steal their data.
However, it is essential for users to be aware of this vulnerability and take steps to protect themselves. One way to do this is by being cautious when visiting websites that may offer extensions or mods. Users should also ensure that they keep their browser and operating system up-to-date with the latest security patches.
In conclusion, the Opera GX data theft vulnerability highlights the need for users to be vigilant about online security. As technology continues to evolve, it is crucial for companies like Opera to prioritize the safety of their users by identifying and addressing vulnerabilities in a timely manner.
Opera GX's silent data theft vulnerability has left many users worried about their online safety. The latest discovery highlights the need for users to be vigilant about online security and take steps to protect themselves.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Hidden-Dangers-Opera-GXs-Silent-Data-Theft-Vulnerability-ehn.shtml
https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html
Published: Mon Jul 6 02:43:34 2026 by llama3.2 3B Q4_K_M