New CSS Attacks Can Bypass Webmail Defenses to Steal Passwords and Tokens
New research shows that content embedded within emails can break out of message boundaries and interfere with webmail interfaces.
Across attack chains affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, these techniques could potentially capture passwords, compromise third-party accounts, leak tokens, hijack trusted user interface actions, and manipulate AI tools that process emails.
The article presents proof-of-concept (PoC) research and does not report any known malicious exploitation. As of August 8, publicly available PoC examples were still accessible.
The researcher stated that Fastmail had fixed two CSS mutation vulnerabilities and that the Proton Mail proxy bypass technique no longer worked when retested. However, Outlook's label-hijacking technique and Gmail's image-set() bypass were reportedly still functional when the research was published on August 6.

The article does not specify whether Outlook's password-capture attack chain has been fully fixed. For webmail providers, it recommends isolating HTML emails within sandboxed iframes and strictly restricting CSS, custom attributes, selection menus, and image requests.
The research follows two main attack paths: abusing HTML and CSS that the webmail system already permits, or creating a discrepancy between what a sanitizer approves and what the browser or application ultimately renders. Both approaches can cross the security boundary between an untrusted message and a trusted user interface.
Outlook demonstrates how these techniques can be combined. Allowed label elements can trigger controls outside the message, while application JavaScript can transform sanitized custom attributes into new DOM nodes containing CSS outside the sanitizer's allowlist. A media-query parsing trick can then provide the attacker with the ability to inject arbitrary CSS.
This attack chain disguises a selection element as a password field. In Firefox, when the selection element moves off-screen, an approximately one-second option-selection timer is reset, enabling password capture to occur in near real time.
Yahoo Mail and AOL Mail revealed a different attack path. In Firefox, pasted HTML could temporarily retain active CSS before the sanitization process was completed. In the demonstrated scenario, an attacker initiates an email login flow, convinces the victim to copy attacker-controlled CSS to the clipboard, and then paste it into a Yahoo or AOL draft. The resulting requests can expose enough information about a 12-character login token for the attacker's server to reconstruct it, potentially allowing the attacker to authenticate as the victim.
The article also presents a click-based data exfiltration technique for situations where Content Security Policy (CSP) blocks external resources. Given a style injection vulnerability and a numeric token displayed as text within an email, CSS can determine which digits appear and how frequently they occur. It can then hide non-matching links while leaving the matching link across the page. When the victim clicks it, information about the digits and their frequency can be transmitted to an attacker-controlled server.
AI-connected email introduces another potential attack path. Gmail's image-set() fallback mechanism can trigger an external request despite sanitization. Heyes and his PortSwigger colleague Pete Hendy connected this behavior to an indirect prompt-injection email processed by Anthropic's Claude Cowork through a connected Gmail integration.
In the demonstrated scenario, an attacker first sends a Slack token confirmation email. When the victim asks Cowork to process their emails, the injected instructions cause the token to be retrieved and placed into an HTML draft. Viewing the draft then results in the token being leaked.
A Fastmail demonstration targeted OpenAI's Atlas AI browser. CSS pseudo-elements and opacity techniques allowed harmless text to be displayed to the human user while hidden instructions remained readable by the AI model. When the user asked Atlas to translate the visible text, the hidden prompt caused browser tabs to be opened and the victim's name to be encoded into URL fragments. OpenAI announced that Atlas was being discontinued and would stop operating on August 9, 2026.
Other findings include Fastmail "CSS hotwiring," which can redirect clicks into unintended, multi-step user interface actions. A Fastmail image-proxy bypass technique using escape characters relied on an allowlisted user.fm domain to reveal when an email was viewed.
As another example, Heyes demonstrated a Proton Mail attack technique capable of exposing the recipient's IP address. Proton's current tracker-protection documentation states that the service is designed to hide users' personal IP addresses and the exact time at which emails are opened.
The accompanying public repository contains Proof-of-Concept (PoC) examples for the disclosed techniques. The defensive guidance begins with strict isolation of email content, followed by character allowlists for CSS validation, verification of CSS-related functionality before allowing custom attributes, blocking selection menus and dangerous selectors, and preventing attacker-controlled image requests and abuse of allowlisted domains.
Particularly in hybrid network architectures involving integrations between on-premises systems and cloud environments, vulnerabilities of this nature can significantly increase an attacker's ability to perform lateral movement. By exploiting weaknesses in authentication and trust mechanisms, attackers may impersonate legitimate service accounts and potentially gain access to databases, critical servers, and endpoints while making malicious activity more difficult to detect.
Some of the measures that can be taken to protect against these types of attacks include;
• Isolating HTML emails in a sandboxed environment.
• Strictly filtering CSS/HTML content and external resource requests.
• Keeping webmail systems up to date and fully patched.
• Using MFA/FIDO2 and limiting session/token lifetimes.
• Implementing prompt injection controls for AI-integrated email systems.
• Monitoring suspicious email and session activities through SIEM/SOC solutions.
For more information or professional assistance, please contact our security experts at. info@zerosecond.ae.





















Comments