RECENT research by Gareth Heyes highlights vulnerabilities in major webmail services due to CSS attacks that can compromise user credentials and manipulate AI-powered tools. Heyes demonstrated how CSS can be exploited to bypass security measures in Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, allowing attackers to steal passwords, hijack sessions, and execute unauthorized actions.
For instance, using CSS features that webmail clients allow, attackers can create deceptive elements in emails, such as disguising a dropdown menu as a password field, capturing sensitive user inputs in real time. Other techniques include leaking login tokens via copy-pasting in Yahoo and AOL emails.
The research also indicates that certain vulnerabilities still exist, with recommendations for webmail providers to enhance security protocols by using sandboxed iframes, restricting CSS, and monitoring for dangerous CSS attributes.