Opera GX Stable
Last updated
Opera GX is a special version of the Opera browser which, on top of Opera’s great features for privacy, security and efficiency, includes special features designed to complement gaming.
Install with winget
$ winget install --id Opera.OperaGX --exact --version 135.0.5973.135Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.
For Intune admins
Stop chasing app updates. Pckgr patches them for you.
Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.
Start free 30-day trialNo credit card required.
Installers · v135.0.5973.135
| Architecture | Type | Scope | Install | Download |
|---|---|---|---|---|
| x86 | EXE | user | Direct | |
| x86 | EXE | machine | Direct | |
| x64 | EXE | user | Direct | |
| x64 | EXE | machine | Direct |
Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.
Security
10 known CVEs via NVD
Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a dif...
The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 cha...
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.
Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter.
Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled poi...
See a CVE that affects your fleet? Push the patched version to Intune in one click with Pckgr - automated patching is the only way to keep up.
Related apps
More from Opera Software or browse chromium, internet, manifestv2.
Frequently asked questions
How do I install Opera GX Stable on Windows?
How do I install Opera GX Stable silently for unattended deployment?
How do I uninstall Opera GX Stable via winget?
Is Opera GX Stable free?
Does Opera GX Stable work on Windows 10?
How do I keep Opera GX Stable up to date?
Recent versions
- 135.0.5973.135latest
- 135.0.5973.126
- 135.0.5973.94
- 135.0.5973.85
- 135.0.5973.57
- 134.0.5954.67
- 134.0.5954.55
- 134.0.5954.44
- 133.0.5932.109
- 133.0.5932.81