<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/h8kWZyKKi" -->

---
title: CSS: The Hidden Threat Lurking in Your Inbox | daily.dev
description: Security researcher Gareth Heyes from PortSwigger has demonstrated that CSS alone — without JavaScript or attachments — can be weaponized to build keyloggers...
canonical: https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CSS: The Hidden Threat Lurking in Your Inbox | daily.dev
og:description: Security researcher Gareth Heyes from PortSwigger has demonstrated that CSS alone — without JavaScript or attachments — can be weaponized to build keyloggers...
og:url: https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki
og:image: https://api.daily.dev/og/posts/h8kWZyKKi.png
og:image:alt: CSS: The Hidden Threat Lurking in Your Inbox
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CSS: The Hidden Threat Lurking in Your Inbox

**[Dark Reading](https://daily.dev/sources/dr)** · 5 min read · 0 upvotes · 0 comments

## Summary

Security researcher Gareth Heyes from PortSwigger has demonstrated that CSS alone — without JavaScript or attachments — can be weaponized to build keyloggers and exfiltrate data from webmail platforms. Presented at Black Hat USA 2026, the research shows CSS has grown powerful enough to bypass traditional script-execution defenses. Heyes found vulnerabilities in major webmail vendors, some of whom dismissed his disclosures only to quietly patch them later. Mitigations include CSS sanitization and image proxies on the webmail provider side, but users have little recourse on their own. The attack surface continues to grow as browsers add new CSS features.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/css-hidden-threat-lurking-inbox>

## Questions this post answers

### Can CSS alone be used to build a keylogger without JavaScript?

Yes, according to security researcher Gareth Heyes of PortSwigger, CSS combined with HTML alone can be used to build a working keylogger capable of stealing sensitive user information, without needing JavaScript or malicious attachments. He describes CSS as having grown powerful enough to function almost like a programming language, though extracting data this way requires more effort than traditional exploits, often relying on techniques like animations.

_Security teams tracking emerging attack surfaces like CSS-based exfiltration can follow research updates on daily.dev._

### How can webmail vendors protect against malicious CSS in emails?

Webmail vendors can isolate incoming messages using a technology that prevents CSS from interfering with the rest of the page, and apply more effective sanitization to stop CSS from breaking out of the message's trust boundary. Security teams are also advised to use an image proxy to add another layer of protection for users, since individual users cannot disable CSS themselves.

_Teams hardening webmail against emerging CSS exploits can track defensive techniques like these on daily.dev._

## Similar posts on daily.dev

- [CSS: The bomb inside your inbox](https://daily.dev/posts/css-the-bomb-inside-your-inbox-qdzucfppp) · Hacker News · 0 upvotes · 0 comments
- [HTML Injection to Data Exfiltration: Weaponizing CSS](https://daily.dev/posts/html-injection-to-data-exfiltration-weaponizing-css-i8mkojwcc) · InfoSec Write-ups · 5 upvotes · 0 comments
- [Novel clickjacking attack relies on CSS and SVG](https://daily.dev/posts/novel-clickjacking-attack-relies-on-css-and-svg-609qdgjok) · The Register · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#css](https://daily.dev/tags/css), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CSS: The Hidden Threat Lurking in Your Inbox","url":"https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki"},"datePublished":"2026-08-05T20:09:08.293Z","dateModified":"2026-09-14T06:40:01.454Z","description":"Security researcher Gareth Heyes from PortSwigger has demonstrated that CSS alone — without JavaScript or attachments — can be weaponized to build keyloggers...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4bbd80d6e92bcd1d0f093cedfb7d98a8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4bbd80d6e92bcd1d0f093cedfb7d98a8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,css,data-exfiltration","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"CSS: The Hidden Threat Lurking in Your Inbox"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/css-the-hidden-threat-lurking-in-your-inbox-h8kwzykki#faq","mainEntity":[{"@type":"Question","name":"Can CSS alone be used to build a keylogger without JavaScript?","acceptedAnswer":{"@type":"Answer","text":"Yes, according to security researcher Gareth Heyes of PortSwigger, CSS combined with HTML alone can be used to build a working keylogger capable of stealing sensitive user information, without needing JavaScript or malicious attachments. He describes CSS as having grown powerful enough to function almost like a programming language, though extracting data this way requires more effort than traditional exploits, often relying on techniques like animations. Security teams tracking emerging attack surfaces like CSS-based exfiltration can follow research updates on daily.dev."}},{"@type":"Question","name":"How can webmail vendors protect against malicious CSS in emails?","acceptedAnswer":{"@type":"Answer","text":"Webmail vendors can isolate incoming messages using a technology that prevents CSS from interfering with the rest of the page, and apply more effective sanitization to stop CSS from breaking out of the message's trust boundary. Security teams are also advised to use an image proxy to add another layer of protection for users, since individual users cannot disable CSS themselves. Teams hardening webmail against emerging CSS exploits can track defensive techniques like these on daily.dev."}}]}
```

