CVE-2019-18624: Opera Mini

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.

Affected products

  • Opera Mini: version 44.1.2254.142553 only; version 44.1.2254.142659 only; version 44.1.2254.143214 only

Published 2019-10-29. Last modified 2026-06-17.