New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens — Swati KhandelwalAug 08, 2026Email Security / Vulnerability [https://blogger.googl

new-css-attacks-can-break-webmail-defenses-to-steal-passwords-and-tokens

What’s new: New research presented at Black Hat USA 2026 reveals vulnerabilities in webmail services such as Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. These vulnerabilities allow attackers to exploit CSS to capture passwords, tokens, and manipulate user interfaces. Proof-of-concept techniques demonstrate various attack chains, including password capture through spoofed sign-in screens and token exfiltration via email interactions. Some vulnerabilities have been patched, but others remain active.

Who’s affected

Users of major webmail services including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail are at risk of having their passwords and authentication tokens stolen through these CSS-based attacks.

What to do

  • Webmail providers should isolate HTML email content in sandboxed iframes.
  • Implement strict character allow lists for CSS validation.
  • Check for CSS gadgets before allowing custom attributes.
  • Block select menus and dangerous CSS selectors.
  • Prevent requests from attacker-controlled images and restrict to allow-listed domains.

Sources