• Sources: research, discussion
  • Summary: PortSwigger research uses CSS and HTML that webmail sanitizers allow to exfiltrate login tokens, and delivers an indirect prompt injection through a Fastmail message that steers OpenAI's Atlas browser. The clients named as tested are Yahoo Mail, AOL Mail, Fastmail, ProtonMail, Gmail, and Outlook, all hosted services, so no affected version numbers apply. The research states the bug that lets an email control the Outlook UI still works because Microsoft did not fix it, and gives no fix status for the other targets. A chain against Medium reaches account takeover when the victim pastes into a draft.
  • Why it matters: The allowed-markup techniques abuse CSS and HTML the sanitizers permit rather than markup they failed to strip, so an allow list is not a defence against that part of the research, which also covers image proxy bypasses and CSS mutation that defeat sanitization directly.

send feedback on this story