Security researcher Gareth Heyes unveiled novel Cascading Style Sheets vulnerabilities at the Black Hat USA 2026 conference in Las Vegas, demonstrating that malicious email content can breach message boundaries. The research exposed severe flaws across major webmail platforms including Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. By weaponizing modern CSS features without requiring JavaScript or attachments, attackers can construct effective keyloggers, hijack user interface actions, exfiltrate sensitive login tokens, and manipulate artificial intelligence tools reading user messages. Demonstrations included spoofing Microsoft login screens to capture recipient credentials in real time and exploiting paste race conditions in browsers. While Fastmail has addressed specific mutation bugs, several vulnerabilities involving spoofing and filter bypasses remained active during disclosures. Experts emphasize that users cannot disable cascading styles, placing the onus on technology vendors to implement strict message isolation, robust content sanitization, and comprehensive proxy defenses to safeguard modern digital communications.
Prepared by Jonathan Pierce and reviewed by editorial team.
Emphasizes corporate accountability and regulatory oversight for major technology providers. Focuses purely on technical vulnerability mechanics and vendor patch timelines. Highlights market competition impacts and private sector cybersecurity resilience requirements.
PortSwigger researcher Gareth Heyes revealed vulnerabilities on August 8, 2026. https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail-defenses.html
No left-leaning sources found for this story.
New CSS Attacks Expose Major Webmail Flaws at Black Hat
The Hacker News The Hacker News Dark Reading Daily.dev PortSwigger Research StreetInsider Bleeping Computer TechCrunch The Verge Ars Technica Wired Forbes Reuters Associated Press Bloomberg ZDNET SecurityWeek InfoSecurity Magazine CyberScoop Help Net Security The Register Dark Reading The Hacker News Daily.dev PortSwigger Research BleepingComputer TechCrunch Ars TechnicaNo right-leaning sources found for this story.
Comments