Affected Systems
Opera GX browser (specific versions not disclosed). Vulnerability allowed malicious websites to install browser extensions without user consent, enabling content extraction from visited pages including email addresses and other sensitive data.
Exploitation Status
Proof-of-concept demonstrated successful extraction of Gmail addresses from single page visits. Patch now available from Opera. No CVE assigned yet. Active exploitation in the wild unknown.
Business Impact
Users of Opera GX were vulnerable to silent surveillance via malicious add-ons installed through drive-by attacks. Attackers could exfiltrate credentials, session tokens, PII, and corporate data from any web page visited after compromise. Particularly concerning for organizations where employees use Opera GX for work-related browsing. Patch availability reduces immediate risk, but unpatched installations remain exposed.
Urgency
🟠Within 24 hours
Recommended Actions
- Identify Opera GX installations across the enterprise using endpoint management tools or browser inventory scans
- Force update Opera GX to the latest patched version on all managed endpoints immediately
- Review installed browser extensions on Opera GX instances for unauthorized or suspicious add-ons installed without user knowledge
- Monitor web proxy and DNS logs for connections to known malicious domains that may have exploited this vulnerability
- Consider blocking or restricting Opera GX in corporate environments if it is not a sanctioned browser, or enforce automatic updates via policy
