CSS:the bomb inside your inbox
portswigger.net | research | #ai-security | #browser-security | #data-exposure | #prompt-injection | #web-security | #email-security | #webmail | #css | #sanitization-bypass | #token-exfiltration
Summary
PortSwigger breaks webmail CSS sanitizers to cross trust boundaries, exfiltrate tokens, control AI browsers by email and steal passwords, with attacks spanning Yahoo, Fastmail, ProtonMail and Gmail.
- Published
- Collected
Skip to content