New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New CSS-based attacks allow email content to break out of its message boundary and tamper with webmail interfaces, enabling password theft, token leaks, and account takeover across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
New CSS attacks allow email content to break out of its message boundary and interfere with webmail interfaces. Researcher Gareth Heyes of PortSwigger demonstrated attack chains affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, steal tokens, hijack trusted UI actions, take over third-party accounts, and manipulate AI tools that read email.