A zero-click vulnerability in the Opera GX browser enables remote attackers to silently install malicious extensions by bypassing internal API restrictions during a visit to a compromised website. The flaw, potentially linked to the "GX Mods" or CSS customization features, circumvents standard user consent prompts, allowing unauthorized extensions to gain elevated privileges. These extensions scrape the Document Object Model (DOM) to reconstruct and exfiltrate sensitive Personally Identifiable Information (PII), specifically Gmail addresses, to attacker-controlled Command and Control (C2) infrastructure. This vulnerability allows for PII theft, session token compromise, and potential Denial of Service (DoS) attacks. Immediate update to the patched Opera GX version is required.
-
Vulnerability Mechanics: Zero-Click Injection
- Bypasses standard browser security prompts for extension installation via a malicious URL visit.
- Targets specific internal API functions within the Opera GX gaming edition to automate installation.
- Potentially leverages the "GX Mods" engine or CSS customization capabilities to execute unauthorized installation scripts.
-
Technical Exploitation: DOM Scraping
- Malicious extensions request broad permissions to monitor active browser tabs and page content.
- Utilizes Proof of Concept (PoC) code to identify and reconstruct fragmented Gmail addresses directly from the DOM.
- Operates silently in the background, requiring no user interaction beyond the initial site navigation.
-
Exfiltration and Impact Assessment
- Stolen PII is transmitted via outbound network traffic to external attacker-controlled C2 infrastructure.
- Risk extends beyond email addresses to include the potential theft of session tokens and browser cookies.
- Secondary exploitation paths include browser instability or complete Denial of Service (DoS) attacks via the malicious extension.
-
Targeted Demographics and Scope
- Specifically impacts the gaming community, the primary user base of the Opera GX browser.
- The zero-click nature significantly increases the success rate of exploitation compared to traditional social engineering.
- Vulnerability is isolated to GX-branded features, distinguishing it from standard Opera Chromium distributions.
-
Remediation and Defensive Strategy
- Mandatory deployment of the latest patched Opera GX version to resolve the internal API bypass.
- Network defenders should monitor for anomalous outbound traffic patterns and PCAPs matching known PII exfiltration signatures.
- End-users are advised to perform manual audits of installed extensions to identify and remove unauthorized entries.
Related posts
- feeds.feedburner.com — Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
- Cybersecuritynews
- Thaicert
- Scworld
- Infosecurity-magazine
- Mallory
- Youtube
- Threat-modeling