E-Ink News Daily

Back to list

CSS: the bomb inside your inbox

PortSwigger researcher Gareth Heyes demonstrates how CSS sanitization in major webmail clients can be bypassed to exfiltrate tokens, steal passwords, and compromise user accounts across Gmail, ProtonMail, Fastmail, and Outlook. The research reveals multiple attack vectors including image proxy bypasses, CSS mutation techniques, and indirect prompt injection via emails.

Background

PortSwigger is a well-known web security research lab. Webmail clients must sanitize untrusted HTML/CSS from emails to prevent XSS, but discrepancies between sanitizers and real browsers can create attack surfaces.

Source
Lobsters
Published
Aug 18, 2026 at 09:30 PM
Score
8.0 / 10