CSS: The Hidden Threat Lurking in Your Inbox
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Security researcher Gareth Heyes from PortSwigger has demonstrated that CSS alone — without JavaScript or attachments — can be weaponized to build keyloggers and exfiltrate data from webmail platforms. Presented at Black Hat USA 2026, the research shows CSS has grown powerful enough to bypass traditional script-execution defenses. Heyes found vulnerabilities in major webmail vendors, some of whom dismissed his disclosures only to quietly patch them later. Mitigations include CSS sanitization and image proxies on the webmail provider side, but users have little recourse on their own. The attack surface continues to grow as browsers add new CSS features.