New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Research presented by PortSwigger’s Gareth Heyes shows that HTML and CSS inside email can break out of the message boundary and manipulate trusted webmail interfaces across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The proof-of-concept chains can capture passwords, leak tokens, hijack UI actions, and even steer AI tools that process email, while several vendors have already fixed or partially fixed some of the issues. #PortSwigger #GarethHeyes #Outlook #Gmail #Fastmail #ProtonMail #YahooMail #AOLMail #Anthropic #Claude #OpenAI #Atlas

Keypoints

  • HTML and CSS in email can escape the message boundary and affect webmail interfaces.
  • An Outlook and Firefox chain can spoof a Microsoft sign-in page and capture passwords.
  • Yahoo Mail and AOL Mail can be abused to expose a Medium login token through pasted CSS.
  • Gmail and Claude Cowork can be chained to exfiltrate a Slack token through prompt injection.
  • Fastmail and Proton Mail showed additional issues, including click hijacking, image-proxy bypasses, and IP leakage.

Read More: https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html