Hidden CSS Tricks in Emails Can Steal Passwords Across Major Webmail Platforms
New research has revealed a concerning weakness in how major webmail platforms handle email content. By exploiting CSS (the styling code used to format web pages), attackers can make content inside an email 'escape' its normal boundaries and interfere with the surrounding webmail interface itself. This means malicious emails could visually blend into trusted parts of the page, tricking users into revealing information they'd normally protect.
The research, conducted by a PortSwigger security expert, tested these attack techniques against widely used services including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The findings show that attackers could potentially capture login passwords, hijack access to linked third-party accounts, steal authentication tokens, and even manipulate trusted-looking buttons or actions within the webmail interface. Worryingly, the research also suggests these techniques could be used to manipulate AI tools that read and summarise email content, opening the door to new forms of manipulation as businesses increasingly rely on AI-assisted inboxes.
While these are primarily browser and email-client-side vulnerabilities that vendors will need to patch, small businesses should be aware that email remains a prime target for sophisticated attacks — not just obvious phishing links, but subtle interface manipulation that's much harder for staff to spot.