New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
According to recent study, information included within an email may cross the message boundary and disrupt the webmail experience.
Passwords can be obtained, third-party accounts can be taken over, tokens can be leaked, trusted user interface activities can be taken over, and AI programs that read emails may be manipulated throughout attack chains involving Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
The work was presented at Black Hat USA 2026 by PortSwigger researcher Gareth Heyes. One Outlook/Firefox chain mimics a Microsoft sign-in screen and records the password that a receiver enters. A Medium email login token may be exposed by a Yahoo/AOL paste race, allowing an attacker to log in as the victim. A Slack token can be exfiltrated by a Gmail/Cowork chain fo...

