Article may be outdated

This article is 55 days old. Some details may have changed since publication.

Hacker News·5 min read·hard

CSS: The bomb inside your inbox

A
ashurandi
CSS: The bomb inside your inbox
✦AI Summary

Security researcher Gareth Heyes details vulnerabilities in webmail clients caused by discrepancies between CSS sanitizers and browser rendering. The paper explains how these flaws can be exploited to compromise user accounts and steal sensitive data.

Why it matters

It exposes critical security risks in widely used webmail platforms, emphasizing the difficulty of safely rendering untrusted HTML/CSS.

✦Dive DeeperCreate a free account to unlock

What's the difference between Pro and DAST?

Download the latest version of Burp Suite.

Published: Thursday, 6 August 2026 at 22:00 UTC

Updated: Thursday, 6 August 2026 at 22:00 UTC

Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes

It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper I'm going to show you how to break out of trust boundaries, exfiltrate tokens, compromise 3rd party websites and even steal passwords.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in