Silent Opera GX Mods Leak Data Across Sites

Opera GX treated a look-and-feel mod like a browser-wide trust decision. A site could drop a GX Mod without a click, and that mod’s CSS followed the user to every page they opened, so a styling feature became a cross-site data channel instead of a page-local tweak. Researchers showed the leak by reconstructing a signed-in user’s full Gmail address from one visit, using CSS rules that tested guesses one letter at a time and only fetched a remote image when the guess matched. Opera says it patched the flaw in Opera GX version 130.0.5847.89 and found no evidence of in-the-wild use. The risk is broader than one email address. Any browser feature that can restyle or observe pages across sites can carry hidden data out of later sessions, even if it cannot run JavaScript or ask for broad permissions.

Part of the PlainSec briefing for 2026-07-06

Sources