New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party …
Intelligence analysis by Llama

A new research paper presented at Black Hat USA 2026 shows how CSS attacks can break webmail defenses to steal passwords and tokens. The techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.
Imagine you're sending an email to a friend, but the email has a secret code that can trick the email program into showing you something it shouldn't. This is like a game of cat and mouse between the email program and the secret code. The email program is trying to keep you safe, but the secret code is trying to trick it. This is what's happening in this research, where the secret code is using CSS to trick the email program into showing sensitive information.
Analysis
CSS Attacks on Webmail: A Growing Concern
The recent research paper presented at Black Hat USA 2026 has shed light on a growing concern in the world of webmail security. The paper, which was presented by PortSwigger researcher Gareth Heyes, demonstrates how CSS attacks can be used to break webmail defenses and steal sensitive information such as passwords and tokens.
The research shows that by exploiting vulnerabilities in webmail interfaces, attackers can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. The techniques used in the research are not only limited to webmail but can also be applied to other areas of web security.
Isolating HTML Email in Sandboxed Iframes
One of the key recommendations made by the research is to isolate HTML email in sandboxed iframes. This can help prevent attackers from exploiting vulnerabilities in the webmail interface and stealing sensitive information. Additionally, webmail providers should tightly restrict CSS, custom attributes, select menus, and image requests to prevent attackers from using these features to their advantage.
Strict Isolation and Character Allow Lists
The research also recommends that webmail providers implement strict isolation and character allow lists for CSS validation. This can help prevent attackers from using CSS to their advantage and stealing sensitive information. Additionally, webmail providers should check for CSS gadgets before allowing custom attributes and block select menus and dangerous selectors to prevent attackers from using these features to their advantage.
Preventing Attacker-Controlled Image Requests
Another key recommendation made by the research is to prevent attacker-controlled image requests and allow-listed domains. This can help prevent attackers from using image requests to steal sensitive information and manipulate AI tools that read email.
Conclusion
In conclusion, the recent research paper presented at Black Hat USA 2026 highlights the importance of webmail security and the need for providers to isolate HTML email in sandboxed iframes and tightly restrict CSS, custom attributes, select menus, and image requests. By implementing these recommendations, webmail providers can help prevent attackers from exploiting vulnerabilities in the webmail interface and stealing sensitive information.
Key points
- CSS attacks can be used to break webmail defenses and steal sensitive information such as passwords and tokens.
- Webmail providers should isolate HTML email in sandboxed iframes and tightly restrict CSS, custom attributes, select menus, and image requests.
- Strict isolation and character allow lists for CSS validation can help prevent attackers from using CSS to their advantage.
- Webmail providers should check for CSS gadgets before allowing custom attributes and block select menus and dangerous selectors.
- Preventing attacker-controlled image requests and allow-listed domains can help prevent attackers from using image requests to steal sensitive information and manipulate AI tools that read email.
If webmail providers implement the recommendations made by this research, it could lead to a significant reduction in the number of CSS attacks on webmail. This could make it much harder for attackers to steal sensitive information and manipulate AI tools that read email.
If webmail providers do not implement the recommendations made by this research, it could lead to a significant increase in the number of CSS attacks on webmail. This could make it much easier for attackers to steal sensitive information and manipulate AI tools that read email.



