Infosecurity-Magazine Critical Opera GX Vulnerability Enables CSS Injection and Data Theft
Article Content
- •Opera GX allows unauthorized installation of GX Mods, enabling CSS injection.
- •Attackers can exfiltrate sensitive data from any site visited by the victim.
- •A denial-of-service attack can occur in Incognito mode, crashing the browser.
A severe vulnerability in the Opera GX browser allows attackers to automatically install GX Mods without user consent, enabling cross-site data exfiltration. This flaw, discovered by researcher zhero_web_security, leverages the GX Mods feature to inject malicious CSS across all visited webpages. The attack can extract sensitive information, such as Gmail addresses, through crafted network requests triggered by the injected CSS. Additionally, this vulnerability poses a risk of denial-of-service (DoS) attacks, causing the browser to crash when a mod is installed in Incognito mode. The issue was reported in February 2026 and was initially rated as low priority but later reassessed as critical. Opera patched the vulnerability on May 8, 2026, and awarded a $5000 bounty to the researcher. The research was published on July 3, 2026, as a proof of concept.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…