PortSwigger researcher Gareth Heyes demonstrates how CSS sanitization in major webmail clients can be bypassed to exfiltrate tokens, steal passwords, and compromise user accounts across Gmail, ProtonMail, Fastmail, and Outlook. The research reveals multiple attack vectors including image proxy bypasses, CSS mutation techniques, and indirect prompt injection via emails.
Background
PortSwigger is a well-known web security research lab. Webmail clients must sanitize untrusted HTML/CSS from emails to prevent XSS, but discrepancies between sanitizers and real browsers can create attack surfaces.
- Source
- Lobsters
- Published
- Aug 18, 2026 at 09:30 PM
- Score
- 8.0 / 10