hacker-news · Crawled Jul 6, 2026

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

1 IoCs
Read original article ↗

AI Summary

A vulnerability in Opera GX allowed malicious websites to silently install browser mods in the form of .crx files without user interaction, enabling attackers to exfiltrate sensitive data such as Gmail addresses via universal CSS injection. The attack exploited the browser's auto-install feature for mods, which applied malicious CSS rules across all visited sites, facilitating cross-site leak (XS-Leak) techniques. Although Opera patched the flaw in version 130.0.5847.89 and found no evidence of in-the-wild exploitation, the zero-click nature of the attack made it highly effective once triggered.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename mod.crx Details →