CSS Attacks Break Webmail Boundaries, Stealing Passwords and Tokens

1 min read
Source: The Hacker News
CSS Attacks Break Webmail Boundaries, Stealing Passwords and Tokens
Photo: The Hacker News
TL;DR Summary

Researchers at Black Hat USA 2026 demonstrated CSS- and HTML-based attack chains that can escape the boundary of webmail interfaces across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail to capture passwords, leak tokens, hijack UI actions, and even manipulate connected AI tools; while some vectors have been patched (Fastmail, Proton Mail), others (Outlook password chain, Gmail image-set() bypass) may still work; PoCs are public, and defense recommendations include isolating HTML emails in sandboxed iframes, tightening CSS validation with allow-lists, blocking dangerous selectors and attacker-controlled image requests, and restricting external resources.

Share this article

Reading Insights

Total Reads

0

Unique Readers

18

Time Saved

3 min

vs 4 min read

Condensed

87%

74093 words

Want the full story? Read the original article

Read on The Hacker News