What happened
Research published August 8 by Gareth Heyes of PortSwigger, working with colleague Pete Hendy, showed that the styling language CSS, a normal part of how emails are formatted, can be weaponized inside major webmail services. The techniques affect Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail in varying ways. Demonstrations included a spoofed Microsoft sign-in screen that captures typed passwords inside Outlook on Firefox, a paste-timing trick in Yahoo and AOL that could expose login tokens, a Fastmail technique the researcher calls CSS hotwiring that redirects clicks into unintended actions, and a Gmail method that abuses image loading to feed hidden instructions to AI assistants reading the mailbox, in one demo extracting Slack tokens. Fastmail fixed two of the reported bugs and an earlier Proton Mail bypass stopped working, but some techniques against Outlook and Gmail still functioned when the research was published.
Why it matters for your business
The uncomfortable part of this research is that it needs no attachment and no malicious link click; the email itself is the weapon, restyling what you see inside a mail client you trust. A fake login prompt that appears inside your real inbox defeats the standard advice of checking the address bar. And if your team uses AI assistants that read email, those assistants become a target too, since hidden content in a message can carry instructions meant for the machine rather than the human.
What to do about it
- Tell your team: your inbox should never ask you to retype your email password mid-read; close the tab and sign in from the provider's site directly
- Keep phishing-resistant MFA, such as passkeys or security keys, on email accounts; stolen passwords matter far less when they are not enough
- If you have connected AI assistants to company mailboxes, review what they can access and whether they process untrusted incoming mail
- Keep browsers and mail clients current as providers roll out fixes
