Dark Reading
Read post

CSS: The Hidden Threat Lurking in Your Inbox

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Security researcher Gareth Heyes from PortSwigger has demonstrated that CSS alone — without JavaScript or attachments — can be weaponized to build keyloggers and exfiltrate data from webmail platforms. Presented at Black Hat USA 2026, the research shows CSS has grown powerful enough to bypass traditional script-execution defenses. Heyes found vulnerabilities in major webmail vendors, some of whom dismissed his disclosures only to quietly patch them later. Mitigations include CSS sanitization and image proxies on the webmail provider side, but users have little recourse on their own. The attack surface continues to grow as browsers add new CSS features.

    #security#css#data-exfiltration
Yesterday•5m read time•From darkreading.com
Post cover image
Table of contents
Design DiscoveriesCSS Is Here to Stay
232 Impressions
Dark Reading's image
Dark Reading

DR (DZone Research) offers insights into software development trends, industry surveys, and technolo...

2.2K Followers

•

745 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard