Preliminary research
One trigram at a time: XSLeak via Universal CSS Injection and DoS in Opera (GX)
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Opera GX installs GX Mods - CRX packages carrying CSS but no JavaScript and no permissions - automatically when a page links or frames the file, giving attacker-controlled CSS on every site the victim visits; in Incognito mode the same primitive crashes the browser. With @import chaining unavailable, the authors encode one static stylesheet that leaks a target value as overlapping trigrams and reassemble it, recovering a victim's Gmail address with no user interaction.
Record
- Researcher
- zhero and inzo_
- Published by
- zhero_web_security
- Date
- Topic
- Injection
In the archive
Related sources
- Earlier CSS import-chaining technique Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of zhero and inzo_, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .