Close Menu
NCIJ Network NCIJ Network
    What's Hot

    11 rumors we’ve investigated about Trump falling asleep

    August 8, 2026

    Jorge Messi: Lionel Messi’s father dies aged 68 after long illness

    August 8, 2026

    X replaces ‘misaligned’ revenue sharing program with Original Content Rewards

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 11 rumors we’ve investigated about Trump falling asleep
    • Jorge Messi: Lionel Messi’s father dies aged 68 after long illness
    • X replaces ‘misaligned’ revenue sharing program with Original Content Rewards
    • N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
    • Bitcoin Red Team Says AI Is Finding Critical Exploits Across Core Projects
    • Meteorite that smashed through a New Jersey roof reveals clues to life’s origins
    • Gaza health chief urges action to ‘save’ Dr Abu Safia before it’s too late | Israel-Palestine conflict News
    • The U.S. Is Burning Through Weapons in Iran. Russia and China Are Taking Note.
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 08, 2026Email Security / Vulnerability

    New research shows content inside an email can escape its message boundary and interfere with the webmail interface.

    Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.

    PortSwigger researcher Gareth Heyes presented the work at Black Hat USA 2026. One Outlook/Firefox chain spoofs a Microsoft sign-in screen and captures the password a recipient types. A Yahoo/AOL paste race can expose a Medium email-login token and let an attacker sign in as the victim. A Gmail/Cowork chain can exfiltrate a Slack token after prompt injection and user interaction.

    The paper presents proof-of-concept research and does not report malicious exploitation. Public PoCs remain available as of August 8. The researcher said Fastmail fixed two CSS mutation bugs and a Proton Mail proxy bypass stopped working when he retested it, while Outlook label-jacking and Gmail’s image-set() bypass still worked when the research was published on August 6.

    The paper does not state whether the full Outlook password-capture chain was fixed. For webmail providers, the paper recommends isolating HTML email in sandboxed iframes and tightly restricting CSS, custom attributes, select menus, and image requests.

    Cybersecurity

    The research follows two paths: abuse HTML and CSS that webmail already allows, or create a discrepancy between what a sanitizer approves and what the browser or application ultimately creates. Both can cross the boundary between an untrusted message and its trusted interface.

    Outlook shows how the pieces can combine. Allowed label elements can trigger controls outside the message, while application JavaScript can turn sanitized custom attributes into new DOM nodes carrying CSS outside the sanitizer’s allow list. A media-query parsing trick then gave the attacker arbitrary CSS.

    The chain disguises a select element as a password field, and Firefox resets its roughly one-second option-selection timer when the select moves offscreen, making capture real-time.

    Yahoo Mail and AOL Mail exposed a different route. In Firefox, pasted HTML could briefly retain active CSS before sanitization. In the Medium demonstration, the attacker initiates an email-login flow, the victim copies attacker-supplied CSS to the clipboard, and then pastes it into a Yahoo or AOL draft. The resulting requests reveal enough of the 12-character login token for the attacker’s server to reconstruct it, which can then be used to sign in as the victim.

    The paper also introduces a click-based exfiltration technique for cases where Content Security Policy (CSP) blocks external resources. Given style injection and a numeric token rendered as text in the email, CSS can determine which digits occur and how often, hide non-matching links, and leave the matching link across the page. A victim click sends the digits and their frequency to the attacker’s server.

    AI-connected email creates another route. Gmail’s image-set() fallback could make an external request despite sanitization. Heyes and PortSwigger colleague Pete Hendy chained it to an indirect prompt-injection email processed by Anthropic’s Claude Cowork through a connected Gmail connector.

    In the demonstrated setup, after the attacker triggered a Slack token confirmation email and the victim asked Cowork to process the emails, the injected instructions caused it to retrieve the token and place it in an HTML draft; viewing the draft leaked it.

    Cybersecurity

    A Fastmail demonstration targeted OpenAI’s Atlas AI browser. CSS pseudo-elements and opacity made the human see harmless text while the model read hidden instructions. When the user asked Atlas to translate the visible text, the hidden prompt caused it to open tabs and encode the victim’s name in URL fragments. OpenAI is deprecating Atlas and says it is scheduled to stop working on August 9, 2026.

    Other findings include Fastmail “CSS hotwiring,” which can redirect clicks into unintended and multi-step UI actions. An escaped-backslash Fastmail image-proxy bypass relies on an allow-listed user.fm domain to reveal when an email is viewed.

    Heyes separately demonstrated a Proton Mail vector that exposed the recipient’s IP address. Proton’s current tracker-protection documentation says the service is designed to hide a user’s personal IP address and exact email-open time.

    The accompanying public repository contains PoCs for the disclosed techniques. The defensive guidance starts with strict isolation, then character allow lists for CSS validation, checks for CSS gadgets before allowing custom attributes, blocking select menus and dangerous selectors, and preventing attacker-controlled image requests and allow-listed domains.

    attacks break CSS defenses Passwords Steal tokens Webmail
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    Critical Vulnerabilities Patched With Chrome 151 Update

    Hackers breach TrueConf to trojanize client installers with backdoors

    Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

    Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    11 rumors we’ve investigated about Trump falling asleep

    August 8, 2026

    Jorge Messi: Lionel Messi’s father dies aged 68 after long illness

    August 8, 2026

    X replaces ‘misaligned’ revenue sharing program with Original Content Rewards

    August 8, 2026

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    August 8, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    11 rumors we’ve investigated about Trump falling asleep

    August 8, 2026

    Jorge Messi: Lionel Messi’s father dies aged 68 after long illness

    August 8, 2026

    X replaces ‘misaligned’ revenue sharing program with Original Content Rewards

    August 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.