| |
CSS: The bomb inside your inbox
Researcher Gareth Heyes demonstrates multiple critical security vulnerabilities in major webmail clients (Gmail, Outlook, Fastmail, ProtonMail, Yahoo Mail, and AOL Mail) by exploiting weaknesses in their CSS and HTML sanitization mechanisms. These vulnerabilities allow attackers to break through trust boundaries, steal authentication tokens and passwords, compromise third-party websites, and perform unauthorized account takeovers through specially crafted emails. The attacks exploit discrepancies between what sanitizers consider safe and what browsers actually render, including abusing allowed HTML elements like labels and bypassing CSS filters.
Read Full Article →
← More Tech news