logo

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

ID: ec579273-e1e4-5a9d-a800-c3953d576adc

STIX ID: report--ec579273-e1e4-5a9d-a800-c3953d576adc

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-08-09

Date Updated: 2026-08-10

Author: Pierluigi Paganini

...
...

PortSwigger research shows that plain CSS in HTML email can be weaponized to break trust boundaries in major webmail services (Outlook, Gmail, Fastmail, Proton Mail, Yahoo, AOL), enabling credential theft, session hijacking, token exfiltration and manipulation of AI-connected inbox tools; several proof-of-concept chains were published, some issues have been patched while others remained exploitable, and mitigations such as sandboxed iframes, strict CSS allow-lists and blocking external image requests are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.