Research · curated 8 Aug 2026
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
First reported portswigger.net
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The CSS-the-bomb research shows that malicious email content can trigger prompt injection against AI assistants that read inboxes, turning a rendering flaw into an agentic data-exfiltration vector defenders must account for.
PortSwigger researcher Gareth Heyes presented at Black Hat USA 2026 a set of CSS-based attacks that let email content escape its message boundary and manipulate the webmail interface across Outlook, Gmail, Fastmail, Proton Mail, Yahoo, and AOL. Beyond capturing passwords and tokens, one Gmail/Cowork chain uses prompt injection to exfiltrate a Slack token, and the techniques can manipulate AI tools that read email; public PoCs remain available and some bugs were fixed by providers.