Microsoft Outlook will no longer show inline SVG images regularly exploited in phishing attacks
- Outlook stops showing inline SVG images to limit phishing and malware risks
- Microsoft continues retiring risky features across Office and Windows platforms for protection
- Company balances user impact with security, ensuring SVG attachments remain fully supported
Malicious use of SVG files has become more and more common in recent years, with attackers relying on the format to deliver malware and build phishing pages.
In response, Microsoft is changing how Outlook handles this type of content and will now prevent inline SVG images from appearing in Outlook for Web or in the new Outlook for Windows.
In a Microsoft 365 Message Center update, the tech giant said, “Inline SVG images will no longer be displayed in Outlook for Web or the new Outlook for Windows. Instead, users will see blank spaces where these images would have appeared.”
A small impact
Microsoft won’t fully be blocking SVG files however.
“SVG images sent as classic attachments will continue to be supported and viewable from the attachment well. This update helps mitigate potential security risks, such as cross-site scripting (XSS) attacks,” the company added.
Microsoft says fewer than 0.1% of images in Outlook use this method, so the impact on typical communication should be minor.
The decision is part of Microsoft’s wider strategy to reduce the number of features that attackers can abuse.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Over the past several years, the company has retired or restricted functions in both Office and Windows that have been used in phishing or malware campaigns.
Earlier in 2025, Outlook Web and the Outlook for Windows began blocking .library-ms and .search-ms files which Bleeping Computer notes had had been exploited in attacks against government targets since at least 2022.
Microsoft has also implemented protections against macros and add-ins in its productivity software. Changes include blocking VBA Office macros by default, adding protection for Excel 4.0 macros, disabling untrusted XLL add-ins and ActiveX controls in Microsoft 365 and Office 2024 apps, and removing support for VBScript.
The full list of formats now blocked is available to view in Microsoft’s documentation here.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
You might also like
Source
Outlook stops showing inline SVG images to limit phishing and malware risks Microsoft continues retiring risky features across Office and Windows platforms for protection Company balances user impact with security, ensuring SVG attachments remain fully supported Malicious use of SVG files has become more and more common in recent years,…
Recent Posts
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Marshall Milton ANC review: Making the rare case for premium on-ear headphones
- Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
- How to watch Spain vs Iraq: Free Streams & TV Channels for World Cup 2026 warm-up match
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023