CVE-2019-12278: Opera

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters. The rendering mechanism, in conjunction with the "first strong character" concept, may improperly operate on a numerical IP address or an alphabetic string, leading to a spoofed URL.

Affected products

  • Opera Opera: version 52.1.2517.139570 only

Published 2020-03-12. Last modified 2026-06-17.