A new security research paper has demonstrated multiple techniques for bypassing CSS sanitization in popular webmail clients, enabling attackers to steal authentication tokens, compromise third-party websites, and even capture passwords.
log in to read full article