CSS Bomb — How Do Hackers Steal Passwords in Emails?

Kun Long • Aug 11, 2026
| 1 min read | 9 views views

CSS Bomb — How Do Hackers Steal Passwords in Emails?

PortSwigger revealed at Black Hat 2026 that a single email can render a fake login screen inside Outlook and steal passwords. Gmail and Yahoo are also affected.

🎯 How it works:
1. Send an email with hidden CSS styling code that bypasses filtering systems.
2. The code escapes the message area and takes control of the email client interface.
3. It renders a fake login screen — no links need to be clicked.
4. Result: The password you type flows straight to the hacker immediately.

⚠️ Lessons for you:
• Do not type passwords in pop-ups from an email — open the app directly and check the URL.
• Turn off automatic image downloads in Gmail and Outlook.
• Do not copy text from strange emails to paste elsewhere.

[Insight: “Don’t click suspicious links” is no longer enough. The application interface itself can lie.]

Kun Long

Author at The Sharing KH

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *