- PortSwigger researcher Gareth Heyes presented CSS-based email attacks at Black Hat USA 2026 on August 8.
- The attacks exploited HTML and CSS techniques in Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL to capture passwords and leak tokens.
- One vector targeted AI-connected email by using CSS to inject hidden instructions into an Anthropic Claude Cowork assistant.
PortSwigger researcher Gareth Heyes presented a series of CSS-based attacks affecting major webmail providers at Black Hat USA 2026 on August 8. The techniques exploit how HTML and CSS can escape an email’s message boundary to interfere with the webmail interface.
One attack chain against Outlook and Firefox spoofs a Microsoft sign-in screen to capture a recipient’s password. Meanwhile, a Yahoo and AOL paste race can expose an email-login token by exploiting how Firefox resets a select element’s timer when it moves offscreen.
A Gmail vector targeting AI-connected email chain uses CSS to inject hidden instructions into Anthropic’s Claude Cowork assistant. When a victim asked the AI to translate visible text, the hidden prompt caused it to retrieve a Slack token and place it in an HTML draft.
Heyes also demonstrated a Proton Mail vector that could expose a recipient’s IP address, contrasting with Proton’s current tracker-protection documentation. Separately, a Fastmail demonstration targeted OpenAI’s Atlas AI browser using CSS pseudo-elements and opacity to hide instructions from humans.
The public repository contains proof-of-concept code for the disclosed techniques. Fastmail fixed two CSS mutation bugs, and a Proton Mail proxy bypass stopped working upon retesting, though Outlook and Gmail issues remained unresolved.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
