New CSS attacks break webmail defenses, stealing passwords, tokens and accounts

New CSS attacks break webmail defenses, stealing passwords, tokens and accounts

PortSwigger researcher Gareth Heyes presented proof at Black Hat USA 2026 that email content can escape its message boundary and interfere with the webmail interface. The attacks span Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail. They allow attackers to capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions and manipulate AI tools that read email.

One attack chain in Outlook and Firefox spoofs a Microsoft sign-in screen and captures the password a recipient types. Another scheme involving Yahoo and AOL uses a paste race to obtain a Medium email-login token, letting an attacker sign in as the victim. In Gmail, a chain involving Cowork can exfiltrate a Slack token after prompt injection and user interaction.

The research is proof-of-concept and does not report malicious exploitation. Public PoCs remained available as of August 8. The researcher said Fastmail fixed two CSS mutation bugs, and a Proton Mail proxy bypass stopped working when he retested it. However, Outlook label-jacking and Gmail's image-set() bypass still worked when the work was published on August 6.

The paper does not state whether the full Outlook password-capture chain was fixed. For webmail providers, it recommends isolating HTML email in sandboxed iframes and tightly restricting CSS, custom attributes, select menus and image requests.

The research follows two paths: abusing HTML and CSS that webmail already allows, or creating a discrepancy between what a sanitizer approves and what the browser or application ultimately creates. Both can cross the boundary between an untrusted message and its trusted interface.

Outlook shows how the pieces combine. Allowed label elements can trigger controls outside the message, while application JavaScript can turn sanitized custom attributes into new DOM nodes carrying CSS outside the sanitizer's allow list. A media-query parsing trick then gave the attacker arbitrary CSS.

The chain disguises a select element as a password field, and Firefox resets its roughly one-second option-selection timer when the select moves offscreen, making capture real-time.

Yahoo Mail and AOL Mail exposed a different route. In Firefox, pasted HTML could briefly retain active CSS before sanitization. In the Medium demonstration, the attacker initiates an email-login flow, the victim copies attacker-supplied CSS to the clipboard, and then pastes it into a Yahoo or AOL draft. The resulting requests reveal enough of the 12-character token.

Tags: Software
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate