Security researchers have identified critical flaws in major webmail providers that allow attackers to exploit untrusted CSS and HTML to compromise user accounts and bypass sanitization filters. These vulnerabilities enable malicious actors to exfiltrate sensitive tokens, manipulate interface elements, and even steal passwords through sophisticated cross-site scripting techniques.