LIVE · cybersecurity feed
Live wire
vulnerability

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, th

zeroday.news · 26d ago

A security vulnerability discovered in the Opera GX browser could allow malicious websites to silently install add-ons and exfiltrate data from visited pages. The flaw, demonstrated by researchers, specifically targets the gaming-oriented version of the Opera browser.

The exploit involves a technique where a compromised or malicious website can trigger the installation of a browser extension without explicit user consent. Once installed, this malicious add-on gains the ability to access and collect information from web pages the user visits.

In a proof-of-concept demonstration, researchers were able to leverage this vulnerability. The specifics of the data that could be stolen were not detailed in the provided information, but the mechanism allows for the extraction of content from web pages.

The core of the issue lies in how Opera GX handles the installation of extensions. While the exact technical details of the vulnerability were not fully disclosed, the implication is that a bypass of standard user permission prompts for extension installation is possible under certain conditions.

This type of vulnerability is particularly concerning because it bypasses a critical security layer designed to protect users from unwanted software. Users typically expect to approve any add-on before it is installed, and this flaw removes that safeguard.

The potential impact of such a vulnerability is significant. Malicious actors could use it to steal sensitive information such as login credentials, financial details, personal messages, or any other data displayed on web pages. The silent nature of the installation means users might not even realize their browser has been compromised.

Opera GX is a popular browser among gamers, often featuring integrations and customizations tailored to the gaming community. The compromise of such a widely used platform could affect a substantial number of users.

While specific mitigation steps from the vendor were not provided, general best practices for browser security remain crucial. These include keeping the browser updated to the latest version, as vendors typically release patches to address discovered vulnerabilities. Users should also be cautious about the websites they visit and the links they click, as these can be entry points for exploits. Additionally, reviewing installed extensions regularly and removing any that are unrecognized or unnecessary can help reduce the attack surface.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.