'CrossBarking' Attack Targeted Secret APIs, Exposing Opera Browser Users
ID: 9665d2eb-69dc-5db6-a6f0-6b57601dc2e9
STIX ID: report--9665d2eb-69dc-5db6-a6f0-6b57601dc2e9
Feed Name: Dark Reading
Threat Score
Guardio disclosed "CrossBarking," a proof-of-concept attack that leverages Opera's private browser APIs by abusing cross-site script injection or a malicious Chrome extension to execute code in the context of privileged domains. The researchers demonstrated the ability to alter settings (including DNS), hijack accounts, disable security extensions, and install malicious extensions; Opera responded by blocking extensions from running scripts on domains with private API access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
