Java applets can be used to read sensitive information – Opera Security Advisories

Severity: Highly Severe
Problem Description

Once a Java applet has been cached, if a page can predict the cache path for that applet, it can load the applet from the cache, causing it to run in the context of the local machine. This allows it to read other cache files on the computer or perform other normally more restrictive actions. These files could contain sensitive information, which could then be sent to the attacker.

Opera’s Response

Opera Software has released Opera 9.60, where this issue has been fixed.


Thanks to Nate McFeters for reporting this issue to Opera Software.