Opera GX: vulnerability in mods allowed silent data scraping from pages without a click

Colleagues, I want to flag a cybersecurity development. A vulnerability was found in Opera GX that allowed a malicious website to silently install a mod and use it to steal data from pages a user visits.
Key points:
— the attack worked with no click and no confirmation;
— the PoC was able to recover a user's full Gmail address;
— Opera has already released a patch in version 130.0.5847.89.
I would recommend checking that your browser is up to date and upgrading as soon as possible.
Why this matters: even a seemingly “decorative” feature can become a leak path if it is given too broad a scope.
Do you review browsers in your team separately from the OS?
#cybersecurity #browsersecurity #vulnerability #privacysafety

