Researchers have discovered that CSS, typically used for styling web pages, can be weaponized in webmail clients to steal user credentials, hijack sessions, and manipulate AI tools. These attacks exploit vulnerabilities in how email clients handle HTML and CSS, allowing malicious styling to interact with the trusted interface. The research highlights risks for major services like Outlook, Gmail, and Yahoo Mail, particularly concerning AI integrations.

A security researcher has demonstrated a series of webmail client vulnerabilities that leverage Cascading Style Sheets (CSS) to steal credentials, hijack sessions, and manipulate AI tools integrated with user inboxes. The research, conducted by Gareth Heyes of PortSwigger, details attack chains against major webmail services including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
The core of these attacks exploits the assumption that CSS, a styling language, cannot interact with elements outside the email message it is applied to. Heyes identified methods to bypass this assumption by either abusing permitted CSS features or exploiting discrepancies between what a content sanitizer approves and what a browser actually renders. This allows untrusted content within an email to interact with the trusted user interface surrounding it.
One particularly concerning attack chain targets Outlook. Heyes found that allowed label elements could trigger controls external to the email. Furthermore, Outlook's JavaScript could transform sanitized custom attributes into new page elements carrying CSS that completely bypasses the sanitizer's rules. This technique was used to disguise a dropdown menu as a password field. In Firefox, the attack could capture typed characters in near real-time because the browser's roughly one-second selection timer resets whenever the dropdown moves off-screen. Heyes described this as a "CSS gadget" where existing JavaScript appends an element to the Document Object Model (DOM) with a CSS property or value not on the webmail CSS sanitizer's allow list, enabling a break out of trust boundaries. Specifically, Outlook's allowance of custom data attributes, combined with a library that appends elements with `position:fixed`, allowed elements to be positioned anywhere on the page, effectively defacing Outlook's interface.
Yahoo Mail and AOL Mail were susceptible to a different vector involving copy and paste in Firefox. HTML pasted into a draft could briefly retain active styling before sanitization removed it. Heyes exploited this window to leak a 12-character login token during a Medium sign-in process. An attacker could initiate a login via email, create malicious CSS to copy to the clipboard, and if the victim pasted it into a draft, the token would be stolen.
Even in scenarios where Content Security Policy (CSP) blocks external resource requests, CSS alone could be weaponized. If a numeric token was displayed as plain text in an email, CSS could determine which digits appeared and their frequency. By carefully arranging links with selectors and visibility rules, a single click could then reveal this information to an attacker's server without requiring JavaScript.
The research also highlighted significant risks to AI tools connected to email inboxes. In Gmail, an `image-set()` fallback could trigger an external request despite sanitization. Heyes chained this into an indirect prompt-injection email processed by Anthropic's Claude Cowork, which was integrated with Gmail. The injected instructions caused the AI to retrieve a token and place it in an HTML draft, leading to its exposure upon viewing. A separate demonstration against OpenAI's Atlas browser used hidden CSS pseudo-elements to present harmless text to a human while an AI model read a different, hidden instruction.
While some providers have addressed reported issues, others remain vulnerable. Fastmail patched two CSS mutation bugs reported by Heyes, and a Proton Mail proxy bypass was no longer effective upon retesting. However, Outlook's label-jacking technique and Gmail's `image-set()` bypass were still functional as of August 6, and it is unconfirmed whether the full Outlook password-capture chain has been resolved.
Proof-of-concept code has been made public alongside the research. Heyes and PortSwigger recommend that webmail providers isolate HTML email within sandboxed iframes, restrict CSS to strict character allow-lists, check for dangerous CSS gadgets before permitting custom attributes, and block image requests to any domain not on an approved list. These measures aim to mitigate the risks posed by weaponized stylesheets.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets