CSS: Cascading Sheep Slaughter (Your Webmail Is a Leaky Barn)

CSS: Cascading Sheep Slaughter (Your Webmail Is a Leaky Barn)

I am going to say something that will shock precisely nobody who has read my previous fourteen articles on this subject: the webmail paradigm was always a catastrophic idea.

Always. From day one. I said it in 1998 and I am saying it again now.

A researcher at PortSwigger, one Gareth, has demonstrated that content inside an email can simply... escape its container. Walk right out. Wander through the webmail interface like a lamb with no fence to stop it. We are talking Outlook, Gmail, Proton Mail, Yahoo Mail, and yes, apparently AOL Mail, which I am disturbed to learn still exists.

The attack vector is CSS. Cascading Style Sheets. The decorative nonsense the Flock uses to make their newsletters look "pretty." It turns out that if you craft your CSS with sufficient malice, it bleeds out of the message boundary and starts interfering with the surrounding interface. Passwords captured. Tokens leaked. Trusted UI elements hijacked. The Wolves are essentially rearranging the barn from inside the envelope.

They are also, and I want you to sit down for this, manipulating the AI tools that read your email for you. The AI. Reading your email. For you. I need a moment.

In my day, the Electric Fence was a physical concept you could audit with your own hands. Your data lived on magnetic tape in a locked room. Nobody's stylesheet was "leaking" anywhere because there was no stylesheet. There was a command prompt and a healthy sense of personal responsibility.

Now the Shepherds have moved everything into the Sky Pasture, handed the Lambs a browser, and called it "enterprise-grade security." And they are baffled, absolutely baffled, when the CSS opens a hole in the fence and the Coyote wanders in wearing a phishing vest.

Modern tools are soft. I have said it before. I will say it on my deathbed.

Remediation

Since apparently we cannot go back to plain-text email over dial-up (I have asked), here is what you do:

Disable HTML email rendering entirely. Yes, the Flock will complain. Let them complain. Complaints are audible. Breaches are silent.

Apply available shearing immediately. Patches exist. Dip your systems. Do not wait for a convenient window.

Audit what your AI assistant can access inside your inbox. If the answer is "everything," that is not a feature, that is a liability with a friendly interface.

Treat every HTML email as a potential fake grain scenario. Because, statistically, several of them are.

The Electric Fence only works if you actually maintain it. Radical concept, I know.

Stay paranoid, the wolves certainly are.


Original Report: https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html