New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
AI Generated Image

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

The Hacker News technology

Key Points:

  • New research by PortSwigger's Gareth Heyes reveals that email content can bypass message boundaries and interfere with webmail interfaces across major providers like Outlook, Gmail, Yahoo Mail, Proton Mail, Fastmail, and AOL Mail, enabling password theft, account takeover, token leakage, UI hijacking, and manipulation of AI tools processing emails.
  • Demonstrated attack chains include spoofing Microsoft sign-in screens in Outlook/Firefox to capture passwords, exploiting paste races in Yahoo/AOL to steal Medium login tokens, and exfiltrating Slack tokens via Gmail/Cowork prompt injection; some vulnerabilities remain unpatched as of August 2026.
  • The research highlights two main exploitation methods: abusing allowed HTML/CSS features within emails or exploiting discrepancies between sanitizers and browser rendering, with Outlook notably combining multiple techniques to bypass security and capture credentials in real time.
  • Additional attacks involve CSS-based click exfiltration despite Content Security Policy restrictions, AI-targeted prompt injections in Gmail linked to Anthropic's Claude Cowork, and Fastmail vulnerabilities that manipulate UI elements and leak user activity, while Proton Mail leaks recipient IPs despite tracker protections.
  • The study recommends strict HTML email sandboxing, tight CSS and attribute restrictions, blocking risky elements like select menus, and preventing attacker-controlled image requests; proof-of-concept code is publicly available to aid defense development.

Trending Business

Trending Technology

Trending Health