
New CSS-Based Attacks Bypass Webmail Defenses, Affecting Major Providers
CybersecurityWebSecurityEmailVulnerabilitiesHackingCSSAttacks
New research reveals that CSS-based attacks can bypass webmail defenses by allowing content within an email to escape its message boundary and interact with the webmail interface. The attack techniques affect multiple major webmail providers, including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Potential impacts include password theft, third-party account takeovers, token leakage, hijacking of trusted UI actions, and manipulation of AI tools that process email. The findings were disclosed by a researcher from PortSwigger, though no specific CVE IDs or dates were provided. No mitigations or patches were mentioned in the reported details.