Researchers disclosed a set of HTML/CSS-only attack chains that let malicious emails break out of normal message boundaries in major webmail clients, enabling password capture, token leakage, UI action hijacking, and even keylogging-like behavior without JavaScript or attachments. The findings, presented by PortSwigger's Gareth Heyes, showed that modern CSS features can be abused to interfere with trusted interface elements in services including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, turning routine email rendering into a path for account takeover and data exfiltration.
The research said some flaws were fixed after disclosure, including two CSS mutation bugs in Fastmail and a Proton Mail proxy bypass that no longer worked on retest, while Outlook label-jacking and Gmail image-set()-based bypasses still worked when the paper was published. Researchers said they found no evidence of active exploitation, but public proof-of-concept techniques remained available, and they urged vendors to isolate HTML email in sandboxed iframes, strengthen sanitization, and more tightly restrict CSS, custom attributes, select menus, and image requests because end users have little practical ability to disable CSS in webmail.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
As of August 8, public proof-of-concept code for the disclosed CSS-based webmail techniques was still available. The research continued to state that it had found no evidence of malicious exploitation.
When the research was published on August 6, PortSwigger said Outlook label-jacking and Gmail's image-set() bypass still worked. These remaining issues showed that some attack chains were still reproducible at publication time.
PortSwigger published research describing multiple HTML/CSS proof-of-concept attack chains against major webmail services, including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The paper said it found no evidence of malicious exploitation, but documented impacts such as password capture, token leakage, UI hijacking, and AI-tool manipulation.
Gareth Heyes presented the CSS-based webmail attack research at Black Hat USA 2026. The presentation detailed how HTML and CSS in emails could escape message boundaries and interfere with trusted webmail interface elements.
The research reported that a Proton Mail proxy-bypass technique no longer worked when retested, indicating the issue had been remediated or otherwise closed. A separate Proton Mail vector exposing the recipient IP address was also described in the research.
PortSwigger's research said Fastmail fixed two CSS mutation bugs identified in the webmail attack research. These fixes were in place by the time the research was publicly discussed.
Gareth Heyes reported flaws, hijacking bugs, and advanced CSS-based attack methods affecting major webmail platforms to vendors. According to the reporting, vendor responses varied, with some responding transparently and others later fixing issues quietly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceportswigger.net
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.