Security researchers from PortSwigger disclosed CSS bomb attacks that exploit CSS styling code in email to hijack webmail interfaces and steal credentials. The technique affects Gmail, Outlook, Yahoo Mail, AOL Mail, Fastmail, and ProtonMail. Attackers use CSS quirks and pseudo-elements to turn emails into invisible keyloggers that capture passwords in real-time. Some flaws have been patched after bug bounty disclosure, but others remain unresolved.
- CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Ke(opens in a new tab)
- New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From(opens in a new tab)
// Get alerts for Google Workspace