CSS: the bomb inside your inbox
It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper [Gareth Heyes] going to show you how to break out of trust boundaries, exfiltrate tokens, compromise 3rd party websites and even steal passwords. Comments
We haven't written up this one. Lobsters has the full story — the link below goes straight to it.