Is Opera GX safe? Explore independent security research, its ownership, data collection and what the evidence says about spyware claims.
Opera GX is safe for everyday use where it counts most. It's a legitimate, actively maintained browser, not malware. It hasn't been shown to secretly transmit data to any government. This answer comes with real caveats. Independent researchers have found and reported genuine vulnerabilities in Opera's browsers over the past few years. Its majority owner is also a Chinese public company, a fact fueling a lot of the "is this spyware" chatter without proving it.
This article is built from published security research, a corporate audit summary, Opera's own regulatory filings and its privacy documentation, not from testing GX's network traffic or source code ourselves. Security, data handling and trust in ownership are three separate questions. The evidence supports different answers to each.
Three things drive most of the concern. They're worth separating.
Ownership. Opera's majority shareholder is a Chinese public company. This single fact gets repeated as shorthand for "untrustworthy" across Reddit threads and YouTube comments. It's a legitimate thing to know about. It isn't, by itself, evidence of wrongdoing.
Data collection. Opera GX is free, ad-supported and collects usage data like most modern browsers do. Some of this is opt-in. Some is on by default with an opt-out. Conflating "collects some data" with "spies on you" is where a lot of the alarm comes from.
Spyware accusations. A widely upvoted Reddit thread asking "So, is Opera GX safe?" captures the general unease well, but the comments there are opinions and anecdotes, not technical findings. They're useful for understanding what people are worried about, not for confirming whether those worries hold up.
None of these three concerns are baseless starting points. None of them, on their own, settle the question either.
Opera GX is made by Opera Norway AS, a subsidiary of Opera Limited, a Cayman Islands-incorporated company headquartered in Oslo, Norway. Opera Limited trades on Nasdaq under the ticker OPRA and files annual reports with the U.S. Securities and Exchange Commission, where the ownership structure is disclosed in detail.
According to Opera's own 2025 annual report (Form 20-F), Kunlun Tech Co., Ltd., a public company listed on the Shenzhen Stock Exchange, indirectly owns approximately 68% of Opera's outstanding ordinary shares, making Opera a consolidated subsidiary of Kunlun. Opera's Executive Chairman is also a controlling shareholder of Kunlun. Because of this concentration, Opera qualifies as a "controlled company" under Nasdaq rules, meaning it's exempt from some governance requirements applying to companies with more distributed ownership.
Opera's own filing acknowledges the obvious follow-up risk directly. Because Kunlun is a China-based public company and its chairman is a Chinese national, they're subject to Chinese law and potential action by Chinese authorities, which might affect their ability to exercise control over Opera. This is Opera's own disclosed risk factor, not outside speculation.
What this doesn't establish is a direct line from "majority owner is a Chinese company" to "the browser hands data to the Chinese government." This would require its own evidence: a specific technical finding, or a legal requirement compelling data transfer. Neither has been demonstrated in the sources this article draws on. Opera's headquarters, its data controller for privacy purposes (Opera Norway AS) and its engineering operations sit in Norway, inside the EU's GDPR framework. This fact doesn't cancel out the ownership question either. It's simply a different fact sitting alongside it. Ownership and operational control are related but distinct questions. The evidence here answers the first more clearly than the second.
Three separate, independently reported vulnerabilities are worth walking through, all already fixed. One of them is the first source in this article naming Opera GX as the tested product, not "Opera's browsers" in general.
The first, nicknamed "MyFlaw" and published by Guardio Labs in January 2024, found a flaw in Opera's My Flow feature, a tool for sharing files and notes between desktop and mobile. Under specific conditions, it let an attacker execute a file on a victim's Windows or Mac computer. The attack required the user to install a malicious browser extension disguised as something benign, then click anywhere on a page the extension opened. Guardio privately reported the issue to Opera in November 2023. Opera shipped a server-side fix within five days, by November 22, 2023.
The second, "CrossBarking", also from Guardio Labs and published in October 2024, described how a malicious extension reached Opera's internal "Private APIs," the code powering features like Pinboards. This let an attacker read cookies, take screenshots, disable other extensions or hijack DNS settings. Guardio demonstrated this by publishing a working proof-of-concept extension, disguised as a cute-puppy add-on, in Google's own Chrome Web Store. Opera deployed a public fix on September 24, 2024. It stated it found no evidence the technique had been used against real users.
Both of those writeups describe issues in "Opera's browsers" broadly, tied to shared Chromium-based infrastructure. Neither singles out Opera GX by name as a distinct, separately tested target.
The third is different. In July 2026, independent researchers going by zhero_ and inzo_ disclosed a flaw in Opera GX's "mods" feature, the system letting GX users customize sounds, themes and CSS styling. Opera's own security blog names this one as an Opera GX-specific fix.
A malicious website was able to force-install a mod with no confirmation prompt, then use CSS injection to read data like a signed-in user's email address off pages the victim visited. It then sent this information out through tracker-style requests, all without a click. As a proof of concept, the researchers reconstructed a Bugcrowd triage analyst's own Gmail address while this analyst was reviewing the report.
The same underlying auto-install behavior also crashed the browser and wiped open tabs when an invalid mod file was forced into a private window, a DoS bug hitting regular Opera too, not only GX. The researchers reported the issue through Opera's Bugcrowd program in February 2026. Opera initially triaged it as low-priority, then reassessed it as critical once the impact was demonstrated. It patched the issue by May 8, 2026, shipped fully in version 130.0.5847.89 and paid a $5,000 bounty. Opera posted its own account of the fix when the researchers published their findings in July 2026. It said it found no evidence of exploitation in the wild.
Two audits cover Opera's free browser VPN. Each one tested something different.
Cure53, a Berlin-based security firm, conducted a white-box assessment, meaning they had access to the source code, of Opera's VPN clients, servers and related infrastructure in September 2021, with the summary report dated March 2022. Seven testers spent 24 person-days across four work packages covering the VPN client, server configuration, the Opera Mini protocol used for VPN config delivery and Opera's security processes. They found 14 issues: eight actual vulnerabilities and six lower-risk weaknesses, five rated high severity and none critical. By the time of the report, eight were fixed and verified, one was partly fixed, three were accepted as low-priority risks, one turned out to be a false alarm and one was still in progress.
This is a real, detailed technical audit, but it covered VPN infrastructure specifically, not Opera GX's browser code, extensions handling or any other feature.
Opera also announced a second audit in September 2024, this time of its free VPN's no-log claim, conducted by Deloitte. According to Opera's published summary of the Deloitte audit, the original Deloitte report itself wasn't found publicly during this research. Deloitte reviewed Opera's VPN infrastructure, server configuration and related documentation between June 18 and August 10, 2024. It concluded the systems were "suitably designed and implemented" to match Opera's own claim the VPN logs no browsing data. This particular audit explicitly covers the free VPN as used in Opera, Opera GX and Opera's mobile apps, making it one of the few sources here naming GX specifically. Even so, it certifies the VPN's no-logging design, not the security of the browser as a whole. It's Opera's own summary of the findings being cited here, not an independently obtained copy of Deloitte's full report.
These are specific, technical terms worth using precisely instead of as a general insult.
Spyware typically means software secretly monitoring a user's activity and sending it somewhere without meaningful disclosure or consent, usually for a purpose the user never agreed to. Malware is the broader category: software designed to damage, disrupt or gain unauthorized access to a system. Neither term accurately describes a browser disclosing its data practices in a public privacy policy, giving users toggles to turn features off and getting covered by mainstream security researchers publishing under their own names. None of this is how genuine spyware typically operates.
What's documented, drawing on the research above, is three separate things worth keeping apart. First, disclosed telemetry and ad-related data processing, described in Opera's own privacy statement and covered below. Second, real but since-patched vulnerabilities a third-party attacker was able to exploit, the Guardio research. Third, an unresolved trust question about ownership and geopolitical exposure, the Kunlun connection, not yet tied to any specific data-handling practice.
To be direct about the limit of what this research shows: nothing in the sources reviewed for this article demonstrates Opera GX intentionally transmits user data to the Chinese government or any other state actor. This describes what the available evidence does and doesn't show, not a guarantee no undisclosed behavior exists. An absence of proof isn't the same as proof of absence. This article doesn't rule out something no public research has looked for.
Based on Opera's Privacy Statement (last updated September 4, 2026), which has a section covering "Opera GX desktop (on Windows and Mac)," here's what applies to the desktop browser:
Usage statistics. On install, Opera generates a random installation ID and collects a Machine ID, hardware specs, OS details and feature-usage data, mainly to debug problems and understand how features get used. Retained up to three years. Opt out via Settings > Privacy and Security > "Help improve Opera by sending feature usage information."
Personalized content and ads. If you use features like the News Feed, Opera builds a lightweight interest profile tied to your browser's random ID, not your identity, using general location (city or country) and the categories of sites you visit. This is consent-based, meaning it's off unless you agree to it. You're free to withdraw consent in Settings at any time. Personalized-ad data is retained for up to a year. Personalized-content data is retained for up to three months.
Crash reports. If the browser crashes, Opera collects version, OS and memory-related data to diagnose the crash. Kept up to five months, with an opt-out in Settings.
Malicious-site checks. Opera checks the domain of sites you visit against threat lists, using a framework including Google Safe Browsing, to warn you about known-bad sites. Opera's policy states this doesn't involve collecting full URLs or processing personal data for this specific purpose. Settings lets you turn it off.
Account and sync data, if you choose to create an Opera account, is handled separately from the anonymous, random installation ID your browser already has. The policy states these two identifiers are never linked to each other.
Opera's privacy statement states directly: "We do not sell users' personal data to anyone, either to monetize or to provide advertising." Separately, regarding ad profiling, it states: "We do not share your personal interests or browsing history with anyone." These are Opera's own published claims, not independently audited ones. No source reviewed for this article verified them through outside testing. What the policy does document clearly is how Opera says it monetizes GX instead: primarily through advertising sold within the browser itself and partner arrangements, using data like a hashed user ID, IP address and general location rather than a sale of raw personal data to third parties.
If a reader's specific concern is "does Opera sell my browsing history to a data broker," the available sources don't provide independent confirmation either way beyond Opera's own denial. This is a question the public record doesn't settle.
Opera's free, built-in VPN encrypts your connection and routes it through Opera's own servers, hiding your IP address from the sites you visit. Per the Deloitte-audit summary above, Opera claims this VPN doesn't log your browsing activity. Deloitte's review supports this claim, based on the design of the system as of August 2024.
This is a real, specific claim about the VPN's server-side logging design. It's a narrower one than "you're anonymous." The VPN doesn't touch anything else about how you use the browser. If you're logged into a website, the site still knows who you are, regardless of what your IP address shows. Cookies still work the same way inside a VPN-protected session. Any other Opera feature (personalized content, crash reporting, ad profiling) keeps working on its own terms unless you separately turn it off. A VPN changes what your network connection reveals. It doesn't change what you tell a website directly, or what the rest of the browser does in the background.
A short, practical list, based on the toggles described in Opera's current privacy documentation:
None of these settings guarantee all data collection stops. They adjust specific, documented features, not some general "off switch" for everything the browser does.
This depends on what you're weighing against what.
If GX's specific features (the built-in stats trackers, Twitch integration, customizable UI) matter enough to you, the security research reviewed here doesn't show an active, unpatched threat serious enough to stop you from using it. The vulnerabilities found here got reported responsibly and fixed, closer to how the security-research process is supposed to work than a reason for alarm on its own.
If what bothers you is the ownership structure itself, no amount of security research changes this fact. Kunlun's majority stake and its own regulatory disclosures about Chinese-authority risk are what they are. This is a judgment call about trust, separate from whether the software itself is currently exploitable.
If you want fewer data flows in general, the opt-outs in the settings menu meaningfully reduce personalized content, ad profiling and usage-statistics collection, though none of them zero out everything a modern, ad-supported browser processes. For a broader look at how Opera GX compares with two other options people weigh against it, see our breakdowns of Brave vs. Opera and Opera vs. Chrome.
