CSS Attacks in Webmail Can Steal Passwords and Tokens—and Direct AI Agents
Discover how CSS attacks in webmail can compromise passwords, tokens, and AI agents, as revealed at Black Hat USA 2026, affecting major email services.
Illustrative image generated with AI
Email HTML and CSS Cross the Interface Boundary
Research by PortSwigger shows how HTML and CSS embedded in an email can interfere with components considered trusted by webmail services.
The techniques, presented by Gareth Heyes at Black Hat USA 2026, affect Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Proofs of concept were available as of August 8.
The issue arises when a mail client:
- rebuilds the DOM after sanitization;
- allows custom attributes or complex CSS constructs;
- sends requests to attacker-controlled resources;
- integrates AI agents and connectors capable of reading or modifying email.
No CVEs or observed malicious exploitation have been reported. The potential severity is nevertheless high: the demonstrated chains can target credentials, tokens, and UI actions.
The exact versions of the affected products were not disclosed.
Outlook Can Turn a Menu into a Password Harvester
Against Outlook in Firefox, the technique combines label elements permitted by the client with application JavaScript. The latter converts sanitized custom attributes into new DOM nodes that can carry CSS not initially authorized.
An additional media-query parsing technique makes it possible to inject arbitrary CSS. The researcher then disguises a select element as a password field.
When the menu is moved off-screen, Firefox resets the option-selection timer, which lasts about one second. This makes it possible to capture characters as they are typed.
The paper does not clarify whether the entire password-capture chain has been fixed. At the time of publication, Outlook’s so-called “label-jacking” technique was still working.
Tokens, Clicks, and IP Addresses Become Exfiltratable Data
In Yahoo Mail and AOL Mail, Firefox’s handling of pasted HTML can temporarily keep CSS active before sanitization. In the demonstration, the victim copies attacker-controlled CSS and pastes it into a draft while signing in to Medium via email.
The resulting requests reveal enough information to reconstruct Medium’s 12-character login token, enabling access to the victim’s account.
Another technique uses style injection and a numeric token displayed in the message. CSS determines which digits appear and how many times, hides incompatible links, and leaves visible the link associated with the correct combination. When the user clicks, the attacker receives the digits and their frequencies, even when the Content Security Policy blocks external resources.
On Proton Mail, an image-proxy bypass no longer worked during a retest. A separate vector could nevertheless expose the recipient’s IP address, despite the service’s documentation stating that it aims to hide the user’s IP address and the exact time a message was opened.
The Chains Involve Gmail, Slack, and AI Browsers
In Gmail, the image-set() fallback can generate external requests despite sanitization. PortSwigger combined it with an indirect prompt injection processed by Anthropic Claude Cowork through the Gmail connector.
After triggering a confirmation message containing a Slack token, instructions embedded in the email induced Cowork to retrieve the token, insert it into an HTML draft, and display it when the draft was opened again.
Fastmail was instead exposed to a technique called “CSS hotwiring,” which could redirect clicks to unintended UI actions. An image-proxy bypass used the permitted user.fm domain to signal that a message had been viewed. Fastmail fixed two CSS mutation bugs.
In a demonstration with OpenAI Atlas, pseudo-elements and opacity showed the user harmless text while the AI browser received hidden instructions. A translation request could therefore induce Atlas to open tabs and encode the victim’s name in URL fragments.
OpenAI is discontinuing Atlas; the service is scheduled to stop working on August 9, 2026.
How to Reduce the Risk
Webmail providers should:
- isolate HTML in sandboxed iframes;
- enforce strict allow-lists for CSS characters and constructs;
- inspect CSS gadgets before permitting custom attributes;
- block
selectmenus and dangerous selectors; - prevent attacker-controlled image requests;
- restrict seemingly trusted domains such as
user.fm; - fix CSS mutations and proxy bypasses;
- separate untrusted content, the interface DOM, and application actions;
- prevent AI agents from executing indirect instructions originating in emails;
- avoid exposing tokens in drafts or viewable content.
For users, no universal workarounds have been identified. It is advisable to avoid pasting unknown CSS or HTML into drafts and, where possible, disable AI connectors authorized to process email automatically.
Sources
This article is an original reworking based on the sources below.




