A Critical Flaw in Opera GX Exposes Users to Data Theft via Malicious Websites
Opera GX, a popular gaming-focused web browser, has been found vulnerable to a critical flaw that allows malicious websites to auto-install unwanted browser extensions and steal sensitive data from visited pages. The issue affects users of the browser’s latest versions on Windows, macOS, and Linux platforms.
The vulnerability, discovered by researchers at cybersecurity firm, CyberNews.work, lies in Opera GX’s built-in mod management system. This system is designed to simplify the process of installing and managing browser extensions, but it appears that a misconfigured API allows malicious websites to bypass security checks and auto-install mods without user consent. Once installed, these mods can access sensitive information from visited web pages, including login credentials and browsing history.
To exploit this vulnerability, an attacker would need to trick a user into visiting a specially crafted website. The malicious site would then use the browser’s API to push the unwanted mod onto the user’s system. From there, the mod could proceed to extract sensitive data or even take control of the browser’s functionality. Researchers have demonstrated that this exploit can be executed in as little as three steps: the attacker sends a victim to a malicious website, the website triggers the mod installation, and the mod begins extracting data from visited pages.
The implications of this vulnerability are significant, particularly for gamers who rely on Opera GX for their online gaming experiences. As Opera GX has integrated several features specifically designed to improve user experience for gamers, such as built-in chat functionality and customizable themes, users may be less aware of potential security risks associated with the browser’s unique architecture.
To put this into perspective, AI-powered vulnerability detection tools have become increasingly effective at identifying software vulnerabilities, but they often rely on human input and review to validate the results. This particular flaw was identified by researchers using a combination of manual analysis and AI-driven code scanning techniques. This highlights the growing importance of incorporating AI-aided security checks into standard cybersecurity protocols.
In light of this discovery, we advise Opera GX users to exercise caution when visiting unknown websites or clicking on unfamiliar links. Additionally, users should ensure that their browser is up-to-date with the latest security patches and consider implementing additional security measures, such as a reputable antivirus solution, to mitigate potential risks associated with this vulnerability.
Source: The Hacker News — 2026-07-06