Repeated attempts to access a target site can trigger address field spoofing – Opera Security Advisories

Severity

Low

Description

The browser address field should always show the correct address for the page that is currently being displayed. By making repeated requests to load a target site in rapid succession, an attacking web site can cause Opera to display the target sites address while the attacking page is still being displayed. During such an attempt, the page loading icon may constantly flicker, indicating that the target page is attempting to load.

Opera’s Response

Opera Software has released Opera 12.12, where this issue has been fixed.

Credits

Thanks to Masato Kinugawa for reporting this issue to Opera Software.