Microsoft Outlook stops displaying inline SVG images used in attacks
ID: 4fa2b89d-3cea-501b-9e17-40eb1ec3554d
STIX ID: report--4fa2b89d-3cea-501b-9e17-40eb1ec3554d
Feed Name: Bleeping Computer
Microsoft has begun globally disabling inline SVG image rendering in Outlook for Web and the new Outlook for Windows (rollout early September–mid October 2025) to mitigate attacks—such as XSS and phishing—abusing SVG files. The change affects under 0.1% of images; classic SVG attachments remain viewable. The report highlights a large increase in SVG-based phishing driven by PhaaS platforms and places this mitigation in the context of other recent Microsoft protections against abused Office/Windows features.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
