Urgent.News

What's breaking now, across thousands of outlets.

Tech

CSS: the bomb inside your inbox

It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper [Gareth Heyes] going to show you how to break out of trust boundaries, exfiltrate tokens, compromise 3rd party websites and even steal passwords. Comments

The recent discovery of security vulnerabilities in webmail clients has raised concerns about potential exploits. Gareth Heyes, a researcher, examined various webmail platforms such as Yahoo Mail, AOL Mail, Fastmail, ProtonMail, GMail, and Outlook. His findings revealed discrepancies in sanitization techniques used by these services, enabling him to break trust boundaries, exfiltrate tokens, compromise third-party websites, and even steal passwords.

One notable vulnerability lies within HTML labels. These elements can target specific form elements by utilizing the label's 'for' attribute. This method often eludes HTML sanitizers, and Heyes discovered that at least three webmail clients were susceptible to this weakness. He found a real bug in Outlook, which allowed him to control the Outlook user interface through an email message. Furthermore, he utilized the label element to target input, button, select, and textarea elements with an ID attribute.

Another technique involves exploiting CSS properties and pseudo-elements. By employing the ':before' and ':after' pseudo-elements, Heyes was able to modify text content within elements and control their visibility. This disparity between what the user sees and what the AI browser perceives can potentially alter the email's context. Additionally, by leveraging indirect prompt engineering, Heyes managed to deceive OpenAI's Atlas AI into executing unauthorized operations, such as exfiltrating user data.

Intriguingly, a colleague's observation led to a related discovery. While copying and pasting an IP address into an email, an unexpected advertisement appeared. This prompted an investigation into the behavior of browsers when confronted with malicious CSS on the clipboard. Firefox emerged as the most promising target, as it allowed inline style tags and background image requests. However, it exhibited limitations, including blocking @import requests and animations.

In conclusion, the research conducted by Heyes highlights significant security flaws in widely-used webmail platforms. These vulnerabilities can be leveraged to perform various malicious activities, emphasizing the need for enhanced security measures and rigorous testing to ensure user safety.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at portswigger.net →

More in Tech

More from Tuesday 18 August →