bug bounty2 articles
Opera GX's Mod Auto-Installer Let Attackers Silently Steal Your Gmail Address With Pure CSS
Researchers discovered a critical flaw in Opera GX that allowed malicious websites to silently auto-install a browser mod (a cosmetic add-on) without any user interaction or approval, then exploit it to steal data from other sites the victim visited. By packing the mod with ~150,000 CSS rules, attackers could reconstruct sensitive information like a Gmail address character by character through a cross-site leak technique, all within seconds of the victim landing on the malicious page. Opera has patched the vulnerability in version 130.0.5847.89, rated it their highest severity (P1), and paid the maximum $5,000 bounty, though the underlying auto-install behavior had been flagged as a risk since 2023.
Chrome Vulnerability Numbers Are Skyrocketing. AI Is Almost Certainly Why.
Google has seen a dramatic surge in Chrome vulnerability discoveries, with the number of internally found flaws jumping from a handful in March to 100 in a single advisory published on May 5, likely due to its use of AI tools. While Google has not explicitly confirmed AI is responsible, the timing aligns with its own statements that AI and automation are helping its teams remediate risks "at an unprecedented rate." Google has been developing AI-powered vulnerability discovery tools such as Big Sleep and CodeMender, and is also among a select group of organisations with access to Anthropic's powerful Claude Mythos model.