FILTERING BY: CLEAR FILTER

Opera GX Zero-Click Vulnerability: Silent Extension Installation and PII Exfiltration

A zero-click vulnerability in the Opera GX browser enables remote attackers to silently install malicious extensions by bypassing internal API restrictions during a visit to a compromised website. The flaw, potentially linked to the "GX Mods" or CSS customization features, circumvents standard user consent prompts, allowing unauthorized extensions to gain elevated privileges. These extensions scrape the Document Object Model (DOM) to reconstruct and exfiltrate sensitive Personally Identifiable Information (PII), specifically Gmail addresses, to attacker-controlled Command and Control (C2) infrastructure. This vulnerability allows for PII theft, session token compromise, and potential Denial of Service (DoS) attacks. Immediate update to the patched Opera GX version is required.


LINK COPIED TO CLIPBOARD