Narrative thread
CSS-Based Web Security Vulnerabilities
Security researchers discover and expose critical CSS injection attacks that enable password theft from major webmail platforms.
2 stories · since Aug 8
Combined activity · last 43 hours peak 2/hr
2 items · 5 AM
Aug 9
How the narrative developed 2 stories
- Aug 8
-
SecurityRunning 1d
Gareth Heyes exposes CSS vulnerabilities in major webmail clients
Security researcher reveals techniques to break CSS sanitization in Gmail, Outlook, Fastmail, ProtonMail and other webmail services.
3 sources -
SecurityRunning 1d
PortSwigger researcher reveals CSS attacks stealing passwords across major webmail services
Techniques bypassing HTML sanitization in Outlook, Gmail, Yahoo Mail and others can capture credentials and tokens, with some fixes deployed but vulnerabilities persisting.
2 sources