Vulnerabilities · 70 days ago
Opera GX treated a look-and-feel mod like a browser-wide trust decision. A site could drop a GX Mod without a click, and that mod’s CSS followed the user to every page they opened, so a styling feature became a cross-site data channel instead of a page-local tweak.
Researchers showed the leak by reconstructing a signed-in user’s full Gmail address from one visit, using CSS rules that tested guesses one letter at a time and only fetched a remote image when the guess matched. Opera says it patched the flaw in Opera GX version 130.0.5847.89 and found no evidence of in-the-wild use.
The risk is broader than one email address. Any browser feature that can restyle or observe pages across sites can carry hidden data out of later sessions, even if it cannot run JavaScript or ask for broad permissions.
2 sources covering this story
Opera GX Flaw Let Sites Auto-Install Mods to Steal Data
Opera GX flaw let sites automatically install mods to steal data from other pages, now patched
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Opera GX patched a flaw that let malicious sites silently install GX Mods and leak a signed-in user’s Gmail address with CSS.
Part of the PlainSec briefing for 2026-07-06