← Back to Tech & Science

Security Researcher Demonstrates CSS Vulnerabilities in Global Email Systems Targeting AI Tools

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON (Aug. 9, 2026) — A security researcher has demonstrated that plain Cascading Style Sheets (CSS) embedded within emails can be weaponized to steal passwords, hijack user sessions, and manipulate artificial intelligence-powered tools across multiple major webmail providers.

Gareth Heyes of PortSwigger revealed the vulnerability on Saturday, showing how malicious actors could bypass standard security filters by exploiting inconsistencies in how email clients sanitize code. The attack vector does not rely on complex JavaScript or executable attachments but instead leverages basic styling rules that are often permitted to ensure emails render correctly for users.

The demonstration highlighted a critical failure in trust boundaries within modern email infrastructure. By embedding specific CSS selectors, an attacker can force the browser rendering the email to make unauthorized network requests. These requests can exfiltrate session cookies or authentication tokens without the user interacting with any visible content beyond opening the message. Furthermore, Heyes showed that these techniques could be adapted to trick AI-integrated features within webmail platforms into processing malicious prompts or revealing sensitive data.

The vulnerability affects a global range of email services where CSS is permitted for formatting purposes. Unlike traditional phishing attacks that rely on social engineering to trick users into clicking links, this method operates silently in the background as soon as the message is loaded. The ability to manipulate AI tools represents a significant escalation, potentially allowing attackers to compromise automated workflows or extract information from conversational agents integrated directly into email interfaces.

Heyes stated the findings were intended to expose weaknesses in how providers handle CSS sanitization and manage the interaction between untrusted content and trusted internal systems. He emphasized that current defenses often focus on blocking scripts while overlooking the potential for abuse within style sheets, which are generally considered safe by default.

Major email service providers have acknowledged receipt of the findings but have not yet released a unified timeline for patches or mitigation strategies. While some clients may already block specific CSS properties used in the demonstration, researchers warn that attackers can likely adapt their code to bypass these initial blocks as defenses evolve.

The incident raises urgent questions about the security architecture of AI-integrated email tools and whether current sanitization standards are sufficient against non-traditional attack vectors. As providers race to update filtering mechanisms, experts advise users to remain vigilant regarding unsolicited emails containing complex formatting or unusual styling elements until comprehensive fixes are deployed across all platforms.

Discussion

0 / 2000