Skip to content

CSS attacks break through security boundaries of webmail clients

Bottom line: Crafted CSS code in emails can manipulate the webmail interface of Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail, compromising passwords, tokens and accounts.

New research findings show that CSS code embedded in emails can break out of its actual message boundary and interfere with the user interface of webmail clients. Affected are Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail.

A researcher from PortSwigger named Gareth has documented several attack chains in which content within an email uses CSS to escape its intended rendering area and manipulate parts of the surrounding webmail interface. The techniques affect common web-based mail clients, including Microsoft Outlook, Google Mail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail.

According to the description, these methods can be used to harvest passwords, take over third-party accounts, exfiltrate tokens, and abuse trusted UI actions of the mail interface for the attacker’s own purposes. It is also noted that AI tools that automatically read and process email content can likewise be manipulated by correspondingly crafted messages.

For CISOs, this creates an attack surface that classic email security measures such as spam and phishing filters do not cover, since the malicious effect arises not from links or attachments but from regular CSS in the HTML part of the message. This potentially affects all users who access emails via the webmail interfaces mentioned in a browser, regardless of the email gateway used.

Since this is a structural weakness in the interplay between HTML/CSS rendering and the separation between message content and client chrome, adjustments on the part of the respective webmail providers are to be expected. Until corresponding patches are available, it is advisable to check whether the webmail clients used within one’s own organization are among the services mentioned, and to raise user awareness of unusual behavior of the mail interface when opening unknown messages.


Source: thehackernews.com · Published August 8, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: