
A security researcher found a serious flaw in Opera GX — the gaming-focused version of the Opera browser — that allowed a malicious website to silently install a browser add-on without any clicks or warnings. Once the add-on was in place, it could read data from any page you visited, including your logged-in accounts.
In a proof-of-concept demonstration, researchers were able to reconstruct a victim’s full Gmail address from a single page visit — no interaction required. Opera has since patched the vulnerability and confirmed it found no evidence that the flaw was ever exploited against real users.
How to check if you’re affected
Affected versions are any Opera GX release older than the July 2026 security patch. To check, open Opera GX, click the Opera logo in the top-left corner, go to Help → About Opera GX, and look at the version number. If your browser has not updated recently, click Update to get the latest version. Keeping your browser up to date is the single most effective step here.
