The Opera GX vulnerability shows how browser customization features can become an unexpected path for data theft when installation controls are not strict enough.

Researchers found that a malicious website could silently install an Opera GX Mod without user interaction. Once installed, the Mod could access pages visited by the user and extract specific information. In the proof of concept, researchers were able to reconstruct a signed-in user’s Gmail address from a single visit.

Opera has patched the issue in Opera GX version 130.0.5847.89 and later, and stated that there was no evidence of exploitation in the wild. Users should confirm that their browser is updated and remove any unknown or unnecessary GX Mods.

The incident is a reminder that browser extensions, mods, and add-ons are not harmless cosmetic features. They can interact with web pages, observe browsing activity, and potentially expose sensitive information if abused.

Organizations should restrict unapproved browser extensions, monitor installed add-ons, enforce browser updates, and separate personal browsing from access to business applications.

The key lesson is that browsers are now full application platforms, not simple web viewers. A small feature designed for personalization can become a data-access channel when attackers find a way to install it without consent.


Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user's full Gmail address from a single visit, with no click. Opera has patched the flaw and says it found no evidence that

Source: Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages via The Hacker News — published 06 Jul 2026.