A newly disclosed vulnerability reveals that seemingly innocuous CSS embedded in emails can be exploited to steal login credentials, hijack authentication tokens, and manipulate AI-powered browsers, all while bypassing webmail providers' security measures This article explores text security. . This vulnerability allows hackers to steal passwords by manipulating how users interact with their email interfaces.
Using pure CSS attribute selectors combined with nested selectors, Heyes demonstrated brute-forcing twelve-character hex authentication tokens, including a real login token belonging to Medium.com, by triggering background-image requests that leaked data character by character. Even when Content Security Policy blocked all external resources, he built a font-height oracle using font-face rules, unicode-range, and CSS animations to measure digit frequency and exfiltrate numeric tokens purely through link clicks, with no scripting required.
Combined with `












