CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

August 5, 2026

Black Hat USA 2026 – Las Vegas – Using email platforms to target users is nothing new in the world of threat actors. Nor is it revolutionary for defenders who've shored up guardrails when it comes to suspicious attachments, malicious JavaScript, and more. But as these well-known threats take command of everyone's attention, another vector remains hidden in plain sight.

While HTML is the structure that powers web pages, Cascading Style Sheets (CSS) address design and presentation of the page. From the text to colors and tags to images, CSS manages how a page is displayed. And according to Gareth Heyes, Web security researcher at PortSwigger, it can be weaponized because of its multiple capabilities.

"It's almost like a programming language now," Heyes says. "CSS was on the back burner and largely ignored. [Now] CSS and HTML alone — no JavaScript, no attachments — are enough to build a working keylogger" stealing sensitive and confidential user information.