New research presented by PortSwigger reveals novel CSS-based attacks that break webmail security boundaries to steal passwords, tokens, and hijack accounts across major providers like Outlook, Gmail, Yahoo Mail, and Proton Mail. These exploits abuse allowed HTML/CSS features or sanitizer discrepancies to escape email isolation, enabling phishing, token exfiltration, and UI manipulation, with some attacks still functional as of early August 2026. The study recommends sandboxing HTML emails and strict CSS restrictions to mitigate these evolving threats.
https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html

