conv.

All stories
Person

Gareth Heyes

PortSwigger security researcher · Security researcher — in 2 stories, 4 quotes on record.

What they said verbatim

“Outlook shows how the pieces can combine. Allowed label elements can trigger controls outside the message, while application JavaScript can turn sanitized custom attributes into new DOM nodes carrying CSS outside the sanitizer's allow list.”

The Hacker News · Aug 7 · PortSwigger researcher reveals CSS attacks stealing passwords across major webmail services

“It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization.”

Portswigger research paper · Aug 5 · Gareth Heyes exposes CSS vulnerabilities in major webmail clients

“Trouble is you can create discrepancies between what the sanitizer thinks is safe and what the browser actually renders.”

Portswigger research paper · Aug 5 · Gareth Heyes exposes CSS vulnerabilities in major webmail clients

“I found a real bug in Outlook which would enable me to control Outlook's UI from an email message. This still works today as Microsoft didn't fix it.”

Portswigger research paper · Aug 5 · Gareth Heyes exposes CSS vulnerabilities in major webmail clients