Preliminary research
One trigram at a time: XSLeak via Universal CSS Injection and DoS in Opera (GX)
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Opera GX installs GX Mods - CRX packages carrying CSS but no JavaScript and no permissions - automatically when a page links or frames the file, giving attacker-controlled CSS on every site the victim visits; in Incognito mode the same primitive crashes the browser. With @import chaining unavailable, the authors encode one static stylesheet that leaks a target value as overlapping trigrams and reassemble it, recovering a victim's Gmail address with no user interaction.
Record
- Researcher
- zhero and inzo_
- Published by
- zhero_web_security
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of zhero and inzo_, first published at the original source. Preserved copies are kept so the citation survives its host.