conv.

All stories

Gareth Heyes exposes CSS vulnerabilities in major webmail clients

Security researcher reveals techniques to break CSS sanitization in Gmail, Outlook, Fastmail, ProtonMail and other webmail services.

Conversation activity · last 2 days peak 2/hr

Peak 2 items in one hour at Aug 9, 6 AM; 3 items over 2 days Aug 8, 3 AM — 1 itemAug 8, 4 AM — no itemsAug 8, 5 AM — no itemsAug 8, 6 AM — no itemsAug 8, 7 AM — no itemsAug 8, 8 AM — no itemsAug 8, 9 AM — no itemsAug 8, 10 AM — no itemsAug 8, 11 AM — no itemsAug 8, 12 PM — no itemsAug 8, 1 PM — no itemsAug 8, 2 PM — no itemsAug 8, 3 PM — no itemsAug 8, 4 PM — no itemsAug 8, 5 PM — no itemsAug 8, 6 PM — no itemsAug 8, 7 PM — no itemsAug 8, 8 PM — no itemsAug 8, 9 PM — no itemsAug 8, 10 PM — no itemsAug 8, 11 PM — no itemsAug 9, 12 AM — no itemsAug 9, 1 AM — no itemsAug 9, 2 AM — no itemsAug 9, 3 AM — no itemsAug 9, 4 AM — no itemsAug 9, 5 AM — no itemsAug 9, 6 AM — 2 itemsAug 9, 7 AM — no itemsAug 9, 8 AM — no itemsAug 9, 9 AM — no itemsAug 9, 10 AM — no itemsAug 9, 11 AM — no itemsAug 9, 12 PM — no itemsAug 9, 1 PM — no itemsAug 9, 2 PM — no itemsAug 9, 3 PM — no itemsAug 9, 4 PM — no itemsAug 9, 5 PM — no itemsAug 9, 6 PM — no itemsAug 9, 7 PM — no itemsAug 9, 8 PM — no itemsAug 9, 9 PM — no itemsAug 9, 10 PM — no itemsAug 9, 11 PM — no itemsAug 10, 12 AM — no itemsAug 10, 1 AM — no itemsAug 10, 2 AM — no itemsAug 10, 3 AM — no itemsAug 10, 4 AM — no itemsAug 10, 5 AM — no itemsAug 10, 6 AM — no itemsAug 10, 7 AM — no itemsAug 10, 8 AM — no itemsAug 10, 9 AM — no items 2 items · 6 AM
Aug 9Aug 10

Summary, timeline and people extracted by Claude from 3 items across 3 sources · 21h ago. Quotes are verbatim.

Security researcher Gareth Heyes published a detailed technical paper demonstrating how CSS and HTML vulnerabilities in webmail clients can be exploited to steal tokens, compromise accounts, deface UI elements, and steal passwords. The research covers weaknesses in sanitizers used by Gmail, Outlook, Fastmail, ProtonMail, Yahoo Mail, AOL Mail and OpenAI's Atlas, including a noted unfixed bug in Outlook involving HTML labels.

  • CSS sanitization in webmail clients contains bypasses allowing attackers to break trust boundaries, exfiltrate tokens, and steal credentials.
  • Vulnerability affects multiple major providers: Gmail, Outlook, Fastmail, ProtonMail, Yahoo Mail, AOL Mail, and OpenAI's Atlas.
  • Research documents specific exploits including HTML label abuse, account takeover techniques, and password stealing methods.
  • At least one known unfixed vulnerability exists in Outlook involving UI control via email-embedded malicious labels.

How it unfolded

  1. Reaction Story gains traction on Hacker News

    The research reaches Hacker News frontpage with score of 66 points and 19 comments, indicating significant interest from the developer and security communities.

  2. Reaction Coverage appears in Dark Reading

    Security news outlet Dark Reading picks up the research and republishes coverage under the headline 'CSS: The Hidden Threat Lurking in Your Inbox'.

  3. Report Heyes publishes CSS vulnerability research

    Gareth Heyes publishes comprehensive paper titled 'CSS: The bomb inside your inbox' detailing multiple attack vectors against webmail clients through CSS and HTML sanitization bypasses.

What people are saying verbatim

“It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization.”

Gareth Heyes, Security researcher · Portswigger research paper · Aug 5

“Trouble is you can create discrepancies between what the sanitizer thinks is safe and what the browser actually renders.”

Gareth Heyes, Security researcher · Portswigger research paper · Aug 5

“I found a real bug in Outlook which would enable me to control Outlook's UI from an email message. This still works today as Microsoft didn't fix it.”

Gareth Heyes, Security researcher · Portswigger research paper · Aug 5