Guardio
Read post

“CrossBarking” — Exploiting a 0-Day Opera Vulnerability with a Cross-Browser Extension Store Attack

Guardio Labs has identified and disclosed a serious Opera browser vulnerability, allowing malicious extensions to exploit Private APIs and perform actions such as screen capturing, browser setting changes, and account hijacking. This vulnerability can be exploited across different extension stores, as demonstrated via a malicious extension that bypassed security measures and was accepted into Google's Chrome Store. The case emphasizes the need for stringent review processes and continuous post-approval monitoring to safeguard against such threats.

    #cyber
Oct 30, 2024•16m read time•From medium.com
Post cover image
Table of contents
“CrossBarking” — Exploiting a 0-Day Opera Vulnerability with a Cross-Browser Extension Store AttackIntro — Browser Sandboxing ConceptionCustomizing Browsers via Private APIsBreaking the Private API Bearier — With ExtensionsThe Art of Extension-Based Code InjectionExploiting Private APIs with a POC ExtensionIf One Store is Closed, Somewhere Another is Open“Privately-Stashing” A Cute Puppy ExtensionThe Final Result — End-to-EndLessons Learned
25 Impressions
Guardio's image
Guardio

Guardio's platform is a resource for cybersecurity professionals and internet users, offering insigh...

0 Followers

•

5 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard