Opera Mini Browser Address Bar Spoof

Disclosed by
Renwa
  • Engagement Opera Public Bug Bounty
  • Disclosed date almost 3 years ago
  • Reward $3,000
  • Priority Unassigned Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Renwa

Custom URI scheme combined with a file download freeze the url which allowed full address bar spoof

Activity