Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft
Technical Analysis
Summary
Hide ▲
Show ▼
PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The disclosure includes proof-of-concept chains for password capture, token theft, click hijacking, and AI-email prompt injection. Several paths were still working when published, while others had already been fixed or stopped working on retest.
Related Happenings
TA488 half-click Outlook Web Access espionage campaign
Campaign
H score42
First: 29.07.2026 18:10
Last: 29.07.2026 18:10
Sources 1
About this happening:
TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...
TA488 half-click Outlook Web Access espionage campaign
CampaignAbout this happening: TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LayerX BioShocking prompt injection against agentic browsers
Technical Analysis
H score30
First: 24.06.2026 19:05
Last: 24.06.2026 19:05
Sources 1
About this happening:
Researchers demonstrated BioShocking, a prompt-injection technique that pushed six agentic browsers and plugins past guardrails and made them copy login credentials fo...
LayerX BioShocking prompt injection against agentic browsers
Technical AnalysisAbout this happening: Researchers demonstrated BioShocking, a prompt-injection technique that pushed six agentic browsers and plugins past guardrails and made them copy login credentials fo...
BrowserOS WebPromptTrap patch release (0.32.0)
Security Patch Release
H score11
First: 29.05.2026 21:07
Last: 29.05.2026 21:07
Sources 1
About this happening:
BrowserOS patched WebPromptTrap in version 0.32.0, closing an indirect prompt-injection flaw that could trick users into approving an authorization step inside the...
BrowserOS WebPromptTrap patch release (0.32.0)
Security Patch ReleaseAbout this happening: BrowserOS patched WebPromptTrap in version 0.32.0, closing an indirect prompt-injection flaw that could trick users into approving an authorization step inside the...
Timeline
-
08.08.2026 11:03 1 articles · 3h ago
PortSwigger publishes webmail HTML/CSS boundary-bypass findings
Initial DisclosurePortSwigger researcher Gareth Heyes published proof-of-concept webmail HTML/CSS boundary-bypass research spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail; when the research was published on August 6, Outlook label-jacking and Gmail's image-set() bypass still worked, while Fastmail fixed two CSS mutation bugs and a Proton Mail proxy bypass stopped working on retest.
Show sources
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens — thehackernews.com — 08.08.2026 11:03
-
08.08.2026 11:03 2 articles · 3h ago
Black Hat presentation details password and token theft chains in webmail
Technical Analysis UpdateAt Black Hat USA 2026, Gareth Heyes presented attack chains showing how crafted HTML/CSS in email can capture passwords in an Outlook/Firefox Microsoft sign-in spoof, expose a Medium email-login token through a Yahoo/AOL paste race, exfiltrate a Slack token through Gmail and Anthropic's Claude Cowork via a connected Gmail connector, and redirect clicks or reveal views in Fastmail and Proton Mail; public PoCs remained available as of August 8.
Show sources
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens — thehackernews.com — 08.08.2026 11:03
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens — thehackernews.com — 08.08.2026 11:03