Webmail CSS flaws can trick connected AI tools
Carefully styled email content can interfere with webmail pages and connected AI tools. Demonstrations showed possible password theft, token theft, and misleading AI instructions.
- Report priority
- Medium
- Targets
- Gmail+6 more
How it works
- An attacker sends email containing HTML and CSS that webmail allows through.
- Differences between filtering and browser rendering can let that content interact with the surrounding webmail page.
- In Gmail, researchers connected this behavior to an indirect prompt injection processed by Claude Cowork.
- In OpenAI Atlas, hidden styling made the AI read different instructions from the human reader.
What to do
If you use Gmail with Claude Cowork connected, or OpenAI Atlas to read email, compare your setup with the researchers' documented scenarios. The reported Outlook label attack and Gmail image-request bypass still worked during testing on August 6, 2026.
Check current security guidance from Microsoft, Google, Anthropic, and OpenAI before connecting these tools to email. Fastmail had patched two reported CSS issues, while the Proton Mail bypass failed during retesting. The research did not establish one universal fix or fixed version for Outlook and Gmail.
Technical details
Affected software: Gmail, Outlook, Claude Cowork, Fastmail, Proton Mail, Yahoo Mail, AOL Mail
Webmail filters untrusted HTML and CSS, but browser rendering can differ from what those filters approved. Demonstrated effects included Outlook interface control, token theft through pasted email content, and indirect prompt injection against Claude Cowork through Gmail. Hidden CSS also made OpenAI Atlas interpret instructions differently from the human reader.
References
- github.com · Chrome-App-Bound-Encryption-Decryption product
- github.com · DumpBrowserSecrets product
- i0.wp.com · image-20.png SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- bleepingcomputer.com · real-emails-hijacked-payments-two-h1-2026-attack-chains BleepingComputer
- darkreading.com · flaws-google-apk-python-agent-to-agent-attack DarkReading
- darkreading.com · flying-eagle-mobile-rat-builder-china DarkReading
- snyk.io · evo-continuous-offensive-security Snyk
- snyk.io · why-we-rebuilt-evo-ai-model-risk-scoring Snyk
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0955 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0958 CERT-FR Advisories
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- cisecurity.org · multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-078 MS-ISAC
- cisecurity.org · multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-076 MS-ISAC
- cyble.com · 72-hour-timeline-credential-based-cyberattack Cyble
- cyble.com · attack-surface-discovery-asset-visibility Cyble
- cisa.gov · bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks Cyble
- cisa.gov · cyber-asset-attack-surface-management-caasm Cyble
- ncsc.gov.uk · external-attack-surface-management-buyers-guide Cyble
- ncsc.gov.uk · active-cyber-defence-2-insights-easm-trials Cyble
- varonis.com · rovoblast Varonis
- bugcrowd.com · one-click-data-exfiltration-via-rovochatprompt-url-parameter-confluence-rovo Varonis
- community.atlassian.com · 3159063 Varonis
- atlassian.com · connectors Varonis
- sygnia.co · when-ransomware-hides-in-onedrive-inside-safepay-exfiltration-play Sygnia
- socradar.io · kynx-stealer-wallets-games-ai-tools SOCRadar
- cheatglobal.com · kynx-stealer-devlog-gelistirici-gunlugu.103891 SOCRadar
- virustotal.com · 4f7e6f33e7e80b17f5c7f59ba45f3e32431b639b7d91c2bda1b26664788c8b8b SOCRadar
- app.any.run · b9590ebb-8a3a-47b9-94f1-0e1ee70767c3 SOCRadar
- github.com · RESEARCH.md (main) SOCRadar
- attack.mitre.org · 001 SOCRadar
- attack.mitre.org · 001 SOCRadar
- attack.mitre.org · 001 SOCRadar
- attack.mitre.org · 003 SOCRadar
- attack.mitre.org · T1082 SOCRadar
- attack.mitre.org · T1083 SOCRadar