CSS Attacks in Webmail Can Steal Tokens and Manipulate AI Agents
Research published on August 9, 2026 by Gareth Heyes, a PortSwigger researcher, describes attacks that can be carried out using only HTML/CSS against
Illustrative image generated with AI
Email Rendering Becomes an Attack Surface
Research published on August 9, 2026 by Gareth Heyes, a PortSwigger researcher, describes attacks that can be carried out using only HTML/CSS against webmail interfaces considered trusted.
The techniques target Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. In certain scenarios, they can allow attackers to:
- alter the interface displayed to the user;
- collect credentials, tokens, and data entered into forms;
- hijack sessions;
- influence AI tools connected to email;
- cause information to be disclosed unintentionally.
The issue stems from the unclear boundary between email content and the application interface. Even when JavaScript in email messages is blocked, CSS can interact with trusted elements already present on the page.
Sanitization and “CSS Gadgets” Can Cross Email Boundaries
Clients allow certain CSS properties after sanitization, but the browser may interpret them alongside elements later added by the application’s JavaScript. These components, known as “CSS gadgets,” can create DOM elements or properties that the filter was not designed to anticipate.
In Outlook, for example, permitted label elements can activate controls outside the message. Client-filtered custom attributes may also be transformed by the platform into new DOM elements.
A generated element can receive position:fixed, a property not included in the CSS allowlist. An attacker can then position it over other parts of the page and alter the interface. In one demonstration, a drop-down menu was made to appear as a password field.
In Firefox, the menu-selection timer, which lasts about one second, can restart when the control disappears from the screen. This behavior makes it possible to capture the victim’s keystrokes in near real time.
Tokens and Data Can Be Extracted Without JavaScript
Yahoo Mail and AOL Mail present another Firefox-specific scenario: HTML content pasted into a draft can temporarily retain its active styling before sanitization.
The technique was applied to Medium’s email-based login flow. The service generates a 12-character hexadecimal token. The attacker starts the process using the victim’s address, induces the token to be copied to the clipboard through CSS, and waits for the code to be pasted into a draft.
The attacker-controlled server can then reconstruct the token and authenticate as the victim.
Content Security Policies do not necessarily eliminate the risk. If the displayed text contains digits, CSS selectors can analyze their visibility and order. The results can be encoded in the arrangement of links and transmitted with a single click, without using JavaScript or making direct requests to external resources.
AI Integrations Increase the Impact
In Gmail, the image-set() function can trigger an external request despite sanitization. The research links this technique to an indirect prompt injection embedded in an email processed by Anthropic Claude Cowork through its Gmail integration.
The malicious instructions caused the agent to retrieve a token and insert it into an HTML draft. Viewing the draft then triggered exfiltration of the content.
The risk also extends to how AI-powered browsers interpret messages. In a demonstration against OpenAI Atlas, hidden CSS pseudo-elements displayed harmless text to the user while presenting the model with a different instruction.
An apparently legitimate request, such as summarizing email, can therefore become a starting point for accessing or disclosing unintended data. Exposure is not uniform: it depends on the provider, browser, HTML filter, and enabled integrations.
Available Fixes and Precautions
Fastmail fixed two CSS mutation bugs reported by Heyes. A Proton Mail proxy bypass no longer worked during a subsequent verification.
No fixes have been reported for the techniques involving Outlook, Gmail, Yahoo Mail, AOL Mail, Firefox, Claude Cowork, or OpenAI Atlas.
Users should keep their webmail clients and browsers up to date, avoid pasting access codes into drafts when the content comes from suspicious messages, and carefully inspect password fields or windows that look unusual. Organizations should also review integrations between email accounts and AI agents, limiting their access to tokens, drafts, and sensitive data.
Sources
This article is an original reworking based on the sources below.




