CSS Bomb emails can steal webmail passwords

Published July 28, 2026

A malicious email can imitate a webmail login box and capture passwords as people type. The technique uses HTML and CSS instead of JavaScript or traditional malware.

Report priority
Medium
Targets
Yahoo Mail+3 more

How it works

  • An attacker sends an email containing carefully arranged HTML and CSS.
  • Differences between the email filter and browser display can let the message create a fake password field.
  • Each typed character can trigger a hidden request to an attacker-controlled server.

What to do

When reading email, do not type credentials into a login box shown inside the message. Treat an unexpected login prompt inside an email as suspicious, regardless of which listed webmail service you use.

Avoid automatically loading remote images when your mail service offers that control. Open the provider's real website in a separate tab before entering a password, and follow its security notices for product-specific fixes.

Technical details

Affected software: Yahoo Mail, AOL Mail, Fastmail, ProtonMail

The attack abuses CSS selectors, pseudo-elements, and form-like email content to create a credential-capture interface. Each character can cause a background image request that reveals the typed value to an attacker-controlled server. Some reported flaws were patched, but no exact version details are supplied here.