By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CSS Attacks Bypass Webmail Security, Steal Passwords

New research has uncovered a novel class of Cascading Style Sheets (CSS) attacks that can bypass the security measures of major webmail providers, enabling attackers to steal sensitive information and compromise user accounts. These attacks exploit the way webmail clients render content, allowing malicious code embedded within an email to break free from its designated message boundary and interact with the webmail interface itself. The vulnerabilities have been demonstrated across a wide range of popular email services, including Microsoft Outlook, Google Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The implications of these attacks are significant, as they can lead to the capture of user passwords, the hijacking of third-party accounts linked to email services, the leakage of authentication tokens, and the manipulation of trusted user interface actions. Furthermore, these CSS exploits can interfere with and potentially hijack AI-powered tools that process email content, such as summarization or response generation features. PortSwigger researcher Gareth Davies, who led the investigation, detailed how these attacks work by leveraging CSS features to create visual distortions or invisible elements that can trick users into revealing information or performing unintended actions. For instance, an attacker could craft an email that, when rendered, causes a hidden input field to appear or a legitimate-looking button to perform a malicious function. The research highlights a critical flaw in the sandboxing mechanisms typically employed by webmail services to isolate email content from the broader application interface. The ability for content within an email to directly manipulate the webmail interface represents a significant departure from traditional email-based threats, which often rely on social engineering or exploiting browser vulnerabilities. These CSS attacks, however, operate at the rendering level of the webmail application itself, making them particularly insidious. The captured passwords could grant attackers access to email accounts and any other services that reuse those credentials. Leaked authentication tokens could allow attackers to impersonate users on connected platforms without needing their passwords. The hijacking of trusted UI actions could lead to users unknowingly authorizing fraudulent transactions or sharing sensitive data. The manipulation of AI tools adds another layer of risk, potentially leading to the generation of misleading information or the exfiltration of data through AI-driven communication channels. The research underscores the ongoing challenges in securing complex web applications against sophisticated adversarial techniques, even those that appear to rely on relatively simple web technologies like CSS. The researchers have provided detailed proof-of-concept demonstrations of these attacks, showcasing their effectiveness across multiple platforms. While specific mitigation strategies are still being developed and rolled out by the affected providers, the findings serve as a critical warning about the evolving threat landscape in email security. Users are advised to remain vigilant about suspicious emails and to consider using dedicated email clients or browser extensions that may offer additional layers of security beyond the standard webmail interface. The ongoing development of more robust sandboxing and content sanitization techniques within webmail clients will be crucial in defending against such novel CSS-based exploits.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.