CSS: the bomb inside your inbox

Executive Summary

PortSwigger research by Gareth Heyes shows that many webmail clients render untrusted CSS in a trusted UI, creating a vector for malicious exploitation. The study details how CSS sanitization is applied, identifies gaps in the process, and demonstrates attacks that can hijack sessions or exfiltrate data via crafted styles.


Intelligence Metadata - Source Publisher: PortSwigger Research - Published Date: 2026-08-06T22:00:00+00:00 - Category: research

"Our kindness may be the most persuasive argument for that which we believe."

— Gordon Hinckley
Source: PortSwigger Research