Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2019, researcher Michał Bentkowski found a way to trigger JavaScript in Gmail’s AMP for Email processing using DOM Clobbering. The reported proof of concept did not bypass AMP’s content security policy or run on Gmail’s domain, so it did not demonstrate Gmail account takeover or script execution with Gmail’s origin privileges. SecurityWeek reported that Google patched the issue before October 12, 2019, and paid Bentkowski $5,000.

What was the Gmail dynamic email flaw?

The issue involved AMP for Email, a format that lets senders include a limited set of interactive AMPHTML components in a message. Gmail processes those messages to display dynamic content, such as interactive elements, within the email. Google’s AMP for Gmail documentation describes the format and instructs senders to build and test AMP messages and register before sending dynamic mail to recipients.

SecurityWeek reported on November 20, 2019, that Michał Bentkowski, then chief security researcher at Securitum, found a way to abuse DOM Clobbering in Gmail’s AMP email implementation. DOM Clobbering is a browser technique in which attacker-controlled HTML elements interfere with names or properties that page code expects to reference, potentially changing how that code behaves. The available report does not establish the precise technical chain or patch internals.

What did the proof of concept demonstrate—and what did it not?

According to SecurityWeek’s contemporaneous account, a crafted email could cause attacker-controlled code to execute when opened. But the demonstrated payload did not defeat AMP’s content security policy (CSP), and it ran on a sandbox AMP domain rather than Gmail’s domain. Those distinctions matter: JavaScript running in that sandbox is not the same as JavaScript running with Gmail’s origin privileges.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
  • Demonstrated: a DOM Clobbering-related flaw could trigger code execution in the constrained AMP email environment described in the report.
  • Not demonstrated: bypass of AMP CSP, JavaScript execution on Gmail’s domain, or takeover of a recipient’s Google account.

Bentkowski told SecurityWeek that Google remained concerned because it did not want opening emails to execute arbitrary JavaScript, which he said could be used to send browser exploits. SecurityWeek also characterized Google’s response as calling the vulnerability “awesome”; the report does not name a Google speaker for that characterization.

Was the issue patched, and why was the bounty $5,000?

SecurityWeek reported that Google received Bentkowski’s report on August 15, 2019, and fixed the issue sometime before October 12 that year. The article reported a $5,000 Google bug bounty. These payment and remediation details are attributed to SecurityWeek’s November 20, 2019 report, rather than an independently confirmed Google disclosure.

The available account does not establish a CVE identifier, severity score, affected-version range, number of affected users, or real-world exploitation. The original Securitum link now redirects to a general Securitum page, so the detailed technical chain cannot be independently reconstructed from that source here.

How does Gmail AMP email work today?

Google’s current AMP email security requirements describe controls for senders and request handling. They are operational rules for sending and rendering AMP email, not evidence that the 2019 flaw remains exploitable.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Area Google’s documented requirement or behavior
Sender authentication The message must pass DKIM, with the signing domain aligned to the message’s From domain, and must pass SPF.
Transport security TLS encryption is required.
DMARC Google recommends a DMARC policy of quarantine or reject, noting that this might be enforced in the future.
AMP email XHR requests Gmail proxies XMLHttpRequests from AMP email; the proxied requests do not contain cookies.
Failure to meet requirements The AMP version may not render, and Gmail may fall back to the message’s HTML part.

These details are in Google’s AMP email security requirements. They explain how Gmail handles compliant dynamic messages now; they should not be read as a claim about the exact mitigation applied in 2019.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can dynamic email content change after delivery?

Yes. Google Workspace Help gives the example of a Google Docs comment notification whose displayed comments update as people reply. Its guidance says the described compliance rules apply when the message is delivered, not to content added afterward. Under that process, an organization’s rule does not re-inspect those later updates. See How dynamic email works with advanced content filtering.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.