gbhackers.com • 6h
CSS Exfiltration Vulnerabilities in Google, Microsoft, and Yahoo Webmail Clients
Researchers from PortSwigger and SonarSource have identified a critical vulnerability class enabling CSS-based data exfiltration within major webmail clients, including Gmail, Outlook, and Yahoo. By leveraging advanced CSS attribute selectors and boundary escape techniques, attackers can bypass email sandboxing to interact with the underlying Document Object Model (DOM). This allows for the exfiltration of sensitive credentials, session tokens, and authentication data via side-channel requests—such as background-image: url()—to attacker-controlled servers. The attack vector further extends to UI hijacking and the manipulation of AI-powered email assistants, potentially leading to full third-party account takeover.