Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On
One page visit was enough to rebuild a signed-in user's Gmail address. Opera has patched the flaw.

Key points
- A flaw in Opera GX let a booby-trapped website install a browser add-on without the user clicking anything.
- In a proof of concept, researchers reconstructed a signed-in user's full Gmail address from a single page visit.
- Opera has patched the flaw and reports no evidence of real-world exploitation.
- The bug bypassed permission prompts by abusing Opera's own trusted install process.
Security researchers have disclosed a flaw in Opera GX, a gaming-focused browser, that let a malicious website quietly install a browser add-on and then use it to scrape data from other pages the victim opened. No prompt appeared. The tab just loaded.
The finding was first reported by The Hacker News. Opera has patched the issue and says its telemetry showed no sign anyone exploited it in the wild.
How did the attack actually work?
Opera GX trusted certain Opera-owned web pages to trigger add-on installs on the user's behalf. Researchers found a way to abuse that trust. A browser add-on, sometimes called an extension or a mod, is a small program that plugs into the browser and can read or modify the pages you visit.
Normally, installing one requires your permission. Here, a malicious site could piggyback on Opera's own install machinery and skip that prompt entirely. Once the add-on was in place, it had the access any add-on would: it could read the contents of tabs the victim opened next.
To prove the point, researchers built a demo add-on that pulled a signed-in Gmail address from a visit to Google. One page load handed over the victim's email identity. From an attacker's view, that's a foothold. An email address tied to an active session is the seed for targeted phishing, where criminals craft fake messages to trick a specific person into surrendering passwords or codes.
We've tracked the broader risk of malicious browser add-ons since June, including in our 18 June round-up Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks, which catalogued shady extensions alongside fileless macOS intrusions. What makes this Opera GX case distinctive is that the install didn't come from a third-party store: it exploited Opera's own trusted channel, which is harder to spot and harder to defend against.
What kind of data was at risk?
Anything visible on a page the victim loaded after the add-on landed. That includes email addresses, account names, message contents, and anything else the browser renders on screen.
It didn't, on its own, expose saved passwords or banking credentials. But page-reading access is a strong platform to build on, and researchers were clear that Gmail was just a demo target.
Has Opera fixed it?
Yes. Opera issued a patch through the browser's normal update channel. The company hasn't published a dedicated security advisory or assigned a CVE identifier.
Opera GX is used by millions of people, many of them younger users drawn by the browser's gaming features and customisation options. That audience is central to why this matters: casual users rarely audit which add-ons are running, and an add-on installed without a prompt won't ring any bells when they check the list later.
What should Opera GX users do?
Open the browser, go to the About page, and confirm it's on the latest version. Restart if prompted.
Then open the Extensions page. Any add-on you don't recognise should go. Change the password on accounts you were signed into during the affected period, starting with your primary email.
Enable two-factor authentication on that email account if you haven't already. It's the single most practical step an ordinary user can take to limit the follow-on damage from a stolen email address.



