Affected Systems
Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries. Specific chains target Outlook/Firefox, Yahoo/AOL/Firefox, Gmail with AI connectors (Cowork), and Fastmail. No CVE assigned. Public proof-of-concept code available as of August 8, 2026.
Exploitation Status
Proof-of-concept research published at Black Hat USA 2026 with public PoCs available. No evidence of malicious exploitation reported. Fastmail patched two CSS mutation bugs; Proton Mail proxy bypass no longer works. Outlook label-jacking and Gmail image-set() bypass remained functional as of August 6, 2026. Patch status of full Outlook password-capture chain unclear.
Business Impact
Attackers can steal credentials, hijack accounts, and exfiltrate authentication tokens by sending specially crafted HTML emails. Demonstrated attacks include real-time password capture via spoofed Microsoft sign-in (Outlook/Firefox), Medium login token theft via clipboard paste race (Yahoo/AOL), and Slack token leakage through AI prompt injection (Gmail/Cowork). Attacks require user interaction but can leverage trusted UI elements. Organizations using affected webmail services for business communication face credential theft and account takeover risk. AI-connected email workflows introduce additional attack surface for token exfiltration.
Urgency
🟡 Within a week
Recommended Actions
- Review email security posture: prioritize isolating HTML email rendering in sandboxed iframes with strict Content Security Policy for Outlook, Gmail, Yahoo Mail, AOL Mail, Fastmail, and Proton Mail deployments
- Monitor authentication logs for unusual sign-in patterns, especially following email interactions; focus on token-based authentication systems (Slack, Medium, third-party OAuth) accessed via webmail
- Disable or restrict AI email assistants (e.g., Claude Cowork, OpenAI Atlas) that process untrusted email content until vendors confirm mitigation of prompt-injection and CSS exfiltration vectors
- Apply available patches: confirm Fastmail CSS mutation fixes are deployed; verify Proton Mail tracker protection is current; test whether Outlook label-jacking and Gmail image-set() bypasses affect your environment
- Educate users to avoid pasting untrusted content into webmail drafts (Yahoo/AOL paste-race vector) and to verify legitimacy of in-email authentication prompts before entering credentials
