CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Opera GX Flaw Allowed Silent Mod Installation to Exfiltrate Gmail Addresses via CSS Injection

July 6, 2026

Researchers discovered a critical vulnerability in Opera GX, the gaming-oriented browser, that enabled malicious websites to silently install browser mods and exfiltrate sensitive data from visited pages. The flaw exploited the browser’s automatic mod installation pipeline, which installed .crx files without user approval when loaded via hidden iframes.

The attack leveraged a technique called universal CSS injection, where a mod’s CSS rules applied to every page the victim visited. By crafting approximately 150,000 CSS rules using attribute selectors, researchers could leak a Gmail address character by character from Google’s account page. The proof of concept reconstructed a signed-in user’s full Gmail address within seconds of visiting a malicious site, with no clicks required.

Opera patched the vulnerability in version 130.0.5847.89 and reported no evidence of exploitation in the wild. The bug bounty program initially rated the issue P3 but upgraded it to P1 (critical) after researchers demonstrated the attack by extracting a triage analyst’s Gmail address during reproduction. Opera paid the maximum $5,000 award.

The same auto-install mechanism also caused browser crashes in private browsing mode for both Opera GX and standard Opera. This vulnerability builds on a similar issue identified by researcher Renwa in 2023, which Opera partially patched by blocking extension escalation but left the underlying auto-install behavior unchanged.

CVEs: CVE-2026-55200, CVE-2026-46817

Companies: Opera, Bugcrowd, Google

Products: Opera GX, Opera Browser