CSS Research Exposes Security Gaps Across Major Webmail Platforms

New proof-of-concept research shows how malicious HTML and CSS inside emails can escape message boundaries and interfere with trusted webmail interfaces. Demonstrated attacks against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail could capture passwords, leak authentication tokens, hijack interface actions, and manipulate connected AI assistants. Some weaknesses have been fixed or no longer work, but Outlook label-jacking and Gmail’s image-set() bypass remained functional when the research was published. No malicious exploitation has been reported, while providers are advised to isolate email content in sandboxed iframes and strictly restrict CSS, attributes, menus, and external image requests.

Reference: thehackernews.com