A critical zero-day vulnerability was discovered in Opera's browser that allowed attackers to execute malicious files using a specially crafted browser extension. The vulnerability was found in Opera's My Flow feature, which has the potential for high security risks. The Guardio Labs research team disclosed the issue to Opera and the company responded promptly with a fix.

12m read timeFrom medium.com
Post cover image
Table of contents
“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s BrowserFrom Opera’s My-Flow To The RCE FlawThe Hidden Built-In ExtensionExploiting Opera-Controlled Domains’ PermissionsInjecting Code Via Extension ManipulationsOvercoming CSP/SRI In a Surprising WaySimulating “My Flow” to Send Malicious PayloadOne Final Catch — From Zero to One ClickFull Scope Exploit Extension POCDisclosure And Working With OperaRemediation And Final Thoughts

Sort: