CSS: the bomb inside your inbox (portswigger.net)lobsters
5 points by refp in lobste.rs · 42m ago · lobsters
> It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper [Gareth Heyes] going to show you how to break out of trust boundaries, exfiltrate tokens, compromise 3rd party websites and even steal passwords.
filed under security