Case · DiggingBeagle record

Hidden HTML prompt injection caused a cross-origin data leak in Opera Neon

Brave researchers showed that Opera Neon's AI assistant processed instructions contained in non-rendered webpage content. Their proof of concept navigated from an attacker-controlled page to the user's authenticated Opera account, recovered the user's email address and leaked it to an attacker-controlled endpoint. Opera validated the proof of concept, reported approximately a 10% reproduction rate in its testing and deployed a fix.

Evidence boundary

Researcher proof of concept against Opera Neon while the product was in Early Access. Brave demonstrated cross-origin data exfiltration, Opera independently reproduced the PoC, and both parties reported that the deployed fix stopped the demonstrated PoC. The Sources do not establish exploitation against ordinary users.

Not yet assessed. The record's Claims and Sources remain available; missing grades do not mean low impact.Assessment method

30-second account

Mechanism and trust boundary

Typed chronology

Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.

  1. Oct 14, 2025
    Event type unspecified

    Brave reports hidden-HTML prompt injection to Opera

    Brave submitted the Opera Neon prompt-injection issue through Bugcrowd.

  2. Oct 14, 2025
    notification

    Vendor notified

  3. Oct 20, 2025
    Event type unspecified

    Opera deploys a production fix

    Opera reports that a fix was in production by 22:17:32 UTC on 20 October 2025.

  4. Oct 20, 2025
    patch

    Fix date recorded

  5. Oct 21, 2025
    Event type unspecified

    Brave confirms the demonstrated PoC no longer works

    Opera reports that the researchers confirmed their PoC no longer worked after the update; Brave's disclosure likewise says follow-up testing found the vulnerability appeared patched.

  6. Oct 23, 2025
    Event type unspecified

    Opera publicly describes the vulnerability and mitigation

    Opera publicly documented its reproduction, risk assessment and remediation work.

  7. Oct 23, 2025
    disclosure

    Public disclosure

Claims & evidence

3 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-OPERA-NEON-HIDDEN-HTMLBrave demonstrated that instructions placed in hidden HTML, including an opacity-zero element, were processed by Opera Neon's AI assistant as actionable content.supported

Basis: reported finding

Permanent Claim anchor
CLM-OPERA-NEON-CROSS-ORIGINThe proof of concept caused Neon to access the user's authenticated Opera account page, extract the user's email address and leak it to an attacker-controlled destination.supported

Basis: reported finding

Permanent Claim anchor
CLM-OPERA-NEON-VENDOR-REPROOpera said it validated the proof of concept but reproduced it with approximately a 10% success rate, assessed exploitation complexity as high, deployed a production fix and reported that the researchers subsequently confirmed their proof of concept no longer worked.supported

Basis: reported finding

Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • The cited Sources do not establish in-the-wild exploitation or victims.
  • Opera reproduced the PoC with an approximately 10% success rate and characterized exploitation complexity as high; this limits repeatability of the demonstrated attack but does not negate the underlying trust-boundary failure.
  • The verified fix applies to the demonstrated PoC and does not establish that every possible indirect-prompt-injection technique is eliminated.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 50

Cite this record

DiggingBeagle. “Hidden HTML prompt injection caused a cross-origin data leak in Opera Neon.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Oct 23, 2025. https://diggingbeagle.com/cases/hidden-html-prompt-injection-caused-a-cross-origin-data-leak-in-opera-neon/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology