Tutanota, an email service dedicated to providing secure message exchange, has admitted to a cross-site scripting (XSS) security flaw that allowed a threat actor to manipulate the email subject when sending it to another address in the service. By tricking the user into forwarding the email, JavaScript code could be executed in the context of the web application. The email service provides end-to-end encryption, which means that the messages are encrypted and decrypted locally, in the contex…