hacker-news · Crawled Aug 10, 2026

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

1 IoCs
Read original article ↗

AI Summary

Researcher Gareth Heyes from PortSwigger demonstrated novel CSS-based attacks that exploit rendering discrepancies in webmail clients to bypass security boundaries, enabling password theft, token leakage, and UI manipulation. The attacks affect multiple providers including Outlook, Gmail, Yahoo Mail, AOL, Fastmail, and Proton Mail, using techniques such as CSS mutation, label-jacking, paste-race conditions, and image-set() fallback abuse to exfiltrate sensitive data or spoof authentication interfaces. While some mitigations have been applied—such as Fastmail fixing CSS mutation bugs and Proton Mail proxy bypass no longer working—several vectors, including Outlook label-jacking and Gmail's image-set() bypass, remained exploitable at time of publication. The research highlights risks in AI-connected email systems, where injected CSS can manipulate AI tools like Anthropic's Cowork or OpenAI's Atlas to leak tokens or perform unintended actions.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo portswigger/css-attack-pocs Details →