// GmailMEDIUM
Security researcher Gareth Heyes disclosed CSS bomb vulnerabilities in Gmail and other webmail services that exploit improper HTML/CSS sanitization. Attackers can craft malicious emails leveraging CSS selectors and mutations to exfiltrate authentication tokens, bypass image proxies to reveal user IP addresses, and spoof login interfaces to capture passwords. Multiple attack techniques work by manipulating the gap between sanitizer expectations and browser rendering of untrusted email content.
// Get alerts for Gmail