Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
ID: ec579273-e1e4-5a9d-a800-c3953d576adc
STIX ID: report--ec579273-e1e4-5a9d-a800-c3953d576adc
Feed Name: Security Affairs
PortSwigger research shows that plain CSS in HTML email can be weaponized to break trust boundaries in major webmail services (Outlook, Gmail, Fastmail, Proton Mail, Yahoo, AOL), enabling credential theft, session hijacking, token exfiltration and manipulation of AI-connected inbox tools; several proof-of-concept chains were published, some issues have been patched while others remained exploitable, and mitigations such as sandboxed iframes, strict CSS allow-lists and blocking external image requests are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
