Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows
ID: 4032ce38-5280-5459-afae-64e4843a686c
STIX ID: report--4032ce38-5280-5459-afae-64e4843a686c
Feed Name: The Hacker News
Cybersecurity researchers (Guardio Labs) disclosed a patched remote code execution vulnerability in Opera and Opera GX called “MyFlaw” that abused the My Flow feature and a built-in extension (Opera Touch Background) to bypass the browser sandbox and execute files on Windows and macOS; the issue leveraged a forgotten landing page lacking content security protections to deliver injected JavaScript and a malicious payload, required pairing/user interaction, and was fixed by Opera in November 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
