A serious vulnerability in Opera GX, the gaming-oriented version of the popular Opera, allowed malicious websites to automatically install browser add-ons without any user interaction. The Opera GX vulnerability was discovered by security researchers, who demonstrated that an attacker could completely reconstruct Gmail from a single visit to a malicious page — without a single click. Opera has already released a patch and states that no exploits for the vulnerability have been detected online.
See also: Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

The vulnerability was found in the way Opera GX handles so-called GX Mods — customization packages that allow users to change sounds, themes, wallpapers, and CSS styling in the browser. These mods are packaged as .crx, similar to classic browser extensions, but they cannot execute JavaScript and do not have special permissions. However, the problem was not in the capabilities of the mods themselves, but in their installation process: Opera GX automatically downloads and activates a mod without any confirmation prompt from the user.
This auto-installation behavior is not new. Researcher Renwa had already spotted it in 2023 and by scaling an installed mod to a full extension, he was able to spoof the browser's address bar. Opera patched that particular attack in March 2023, but left the underlying auto-installation feature — which this new research was based on — intact.
How the Opera GX attack works
The attack exploits a technique known as universal CSS injection. A malicious mod is silently installed via a hidden iframe that loads a .crx. Once installed, the CSS is applied to every page the user visits — not just the malicious one. Unlike regular CSS injection , which is limited to a single page, here the attacker affects every website the user opens in the browser.
CSS itself cannot read and transmit data. However, it can be used to “leak” information piece by piece via attribute selectors : a rule checks whether the value of an attribute (e.g. an email in a hidden field) starts with a specific letter and loads a background image from the attacker’s server only if this is the case. By executing enough such requests, the attacker can reconstruct the value character by character. This technique is called XS-Leak (cross-site leak).
See also: Gravity SMTP: Critical vulnerability in 100,000 WordPress sites

To extract a Gmail, the researchers targeted the page myaccount.google.com/contactemail, which contains the address inside three HTML attributes. They created a mod with about 150,000 CSS rules — one for each possible three-letter part of the address — and used a reconstruction script to combine the results. They first tried four-letter parts, which required 5.6 million rules and about 880 MB of CSS, causing the browser to crash. They downgraded to three-letter parts, which allowed enough overlap for reconstruction.
The impact of the Opera GX vulnerability and protection steps
The attack flow is alarmingly simple: the user visits the malicious page, the mod installs within seconds, and a few lines of JavaScript redirect the browser to the Google account page. The CSS is already loaded, triggering requests that leak the address as the page renders — before the user has a chance to click the “Remove” button that appears in the notification bar. The method is not limited to email addresses: it can extract any value exposed in a page’s markup, such as usernames and other personal information.
Additionally, the researchers documented a second, simpler exploit: loading a .crx in Incognito causes the browser to crash and reveal every open tab. This issue affects both regular Opera and Opera GX, as any .crx triggers the extension installation pipeline, regardless of content.
Opera 's bug bounty team has rated the issue as P1 — the highest severity — and is offering the maximum $5,000 for this critical discovery. The fix was included in Opera GX version 130.0.5847.89 , so users who have an updated version are already protected. No CVE number has been assigned for this issue.
See also: Google Gemini AI built into Opera One and Opera GX

To protect against similar threats, Opera GX users should immediately upgrade to version 130.0.5847.89 or later. In addition, it is recommended to regularly review installed extensions and mods , avoid visiting untrusted websites, and enable policies that require user confirmation for each add-on installation. The existence of a proof-of-concept means that the vulnerability is now known to malicious actors, making immediate updating imperative.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
