CVE-2012-1926: Opera Browser

Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.

Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.

Affected products

  • Opera Opera Browser: up to and including 11.61; version 5.0 only; version 5.02 only; version 5.10 only; version 5.11 only; version 5.12 only; …

Published 2012-03-28. Last modified 2026-06-16.