The Hacker News reported on new research by PortSwigger showing how CSS and HTML content inside email can interfere with trusted webmail interfaces.
The research covered attack chains affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
Demonstrated impacts included password capture, third-party account takeover, token leakage, trusted UI hijacking, and manipulation of AI tools that read email.
One Outlook and Firefox chain spoofed a Microsoft sign-in screen and captured the password typed by the recipient.
A Yahoo and AOL paste-race technique could expose a Medium email-login token and let an attacker sign in as the victim.
A Gmail and Claude Cowork chain showed how prompt injection and user interaction could lead to Slack token exfiltration.
The paper did not report malicious exploitation, but public proof-of-concept material remained available as of August 8, 2026.
New PortSwigger research demonstrates how HTML and CSS permitted within email content can be abused to cross webmail trust boundaries, interfere with trusted interface elements, spoof login experiences, and exfiltrate sensitive tokens.
Inside the Webmail Attack Chain
The research highlights two related failure modes: webmail clients allow attackers to abuse HTML and CSS primitives beyond their intended scope, while sanitizer/parser discrepancies cause systems to interpret or transform previously filtered content into a dangerous form. PortSwigger demonstrated both patterns across multiple webmail environments.
In Outlook, the attack was more complex than simply combining allowed
In Yahoo Mail and AOL Mail, researchers identified a paste-related race condition. When a user pasted specially crafted HTML into a draft, its CSS could execute briefly before the platform completed sanitization. In the proof of concept, researchers used CSS attribute selectors and outbound requests to reconstruct a 12-character Medium email-login token, which they could then use to access the victim’s Medium account.
The Gmail-connected AI attack followed a different chain. PortSwigger combined a Gmail image-proxy bypass with indirect prompt injection against Anthropic’s Cowork Gmail connector. The malicious email instructed Cowork to locate token-bearing content and incorporate it into an HTML draft; when the victim subsequently opened that draft, a CSS image-set() request could transmit the Slack token to an external server.
Compliance That Fixes Itself: Automated Remediation with Hexnode UEM
Automate endpoint remediation to reduce compliance gaps, strengthen security, and ease IT workloads.
The Hexnode Solution
Hexnode UEM can help reduce exposure by enforcing device security baselines, OS and software update policies, application controls, and compliance requirements on managed endpoints used to access webmail and SaaS applications. While CSS webmail vulnerabilities exploit in-browser rendering engines, Hexnode serves as a defense-in-depth safety net at the device and identity boundary, helping limit the broader risk posed by compromised or non-compliant endpoints. Its compliance framework can evaluate factors such as encryption, password-policy adherence, required or blocklisted applications, and device integrity.
Hexnode XDR complements these controls by delivering host-level threat detection and rapid response. If a webmail or browser exploit attempts post-compromise payload execution or unauthorized process spawning, security teams can leverage Hexnode XDR to quarantine malicious files, kill compromised processes, and isolate affected endpoints to prevent lateral movement.
For identity-driven access control, Hexnode UEM can integrate with Microsoft Entra ID by sharing managed-device compliance status with Entra ID, where that status can be evaluated as part of Conditional Access decisions. Organizations can then configure Conditional Access policies to grant access to protected corporate resources only when devices managed and evaluated by Hexnode meet defined compliance requirements, reducing reliance on credentials alone as the access boundary.
Feature Resource
Becoming a UEM blackbelt
Explore how Hexnode helps you master UEM—one belt at a time, from enrollment to automation.
The PortSwigger research shows why enterprise email security cannot stop at message filtering. When untrusted email content can interact with trusted webmail interfaces, browsers, identity workflows, or AI-connected tools, the attack surface extends beyond the inbox itself.
Enterprises should take a layered approach that combines browser and endpoint hardening, device compliance, identity-aware access controls, AI connector governance, and continuous endpoint threat monitoring. The objective is to reduce the opportunities for a malicious message to turn an initial webmail weakness into credential theft, token exposure, or broader account compromise.
Try Hexnode free for 14 days
Strengthen endpoint security with Hexnode. Sign up for a free trial today.
I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.