Microsoft Outlook will no longer show inline SVG images regularly exploited in phishing attacks

  • Outlook stops showing inline SVG images to limit phishing and malware risks
  • Microsoft continues retiring risky features across Office and Windows platforms for protection
  • Company balances user impact with security, ensuring SVG attachments remain fully supported

Malicious use of SVG files has become more and more common in recent years, with attackers relying on the format to deliver malware and build phishing pages.

In response, Microsoft is changing how Outlook handles this type of content and will now prevent inline SVG images from appearing in Outlook for Web or in the new Outlook for Windows.

In a Microsoft 365 Message Center update, the tech giant said, “Inline SVG images will no longer be displayed in Outlook for Web or the new Outlook for Windows. Instead, users will see blank spaces where these images would have appeared.”

A small impact

Microsoft won’t fully be blocking SVG files however.

“SVG images sent as classic attachments will continue to be supported and viewable from the attachment well. This update helps mitigate potential security risks, such as cross-site scripting (XSS) attacks,” the company added.

Microsoft says fewer than 0.1% of images in Outlook use this method, so the impact on typical communication should be minor.

The decision is part of Microsoft’s wider strategy to reduce the number of features that attackers can abuse.

Over the past several years, the company has retired or restricted functions in both Office and Windows that have been used in phishing or malware campaigns.

Earlier in 2025, Outlook Web and the Outlook for Windows began blocking .library-ms and .search-ms files which Bleeping Computer notes had had been exploited in attacks against government targets since at least 2022.

Microsoft has also implemented protections against macros and add-ins in its productivity software. Changes include blocking VBA Office macros by default, adding protection for Excel 4.0 macros, disabling untrusted XLL add-ins and ActiveX controls in Microsoft 365 and Office 2024 apps, and removing support for VBScript.

The full list of formats now blocked is available to view in Microsoft’s documentation here.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Intuit reveals new AI agents in a bid to help SMBs across the world grow and prosper

Intuit unveils five new AI agents to help SMBs growReport finds "daily grind" tasks are holding many backNew tools should help unlock productivity for...

Sony is making a Horizon MMO — here’s the video and details

The rumored MMO set in Sony’s post-apocalyptic Horizon universe is real — and we’ve seen a video spilling details about the game before it’s...

Optus Black Friday deals include half price iPhone 16e and AU$180 off NBN

We’re still technically a couple of weeks out from the official start of Black Friday sales in Australia, yet it seems Optus is one...

DP World Tour Championship 2025 live stream: how to watch golf online for FREE, Round 1 tee times

DP World Tour Championship 2025: Thursday, November 13 to Sunday, November 16FREE stream: DP World Tour YouTube (select groups)US streams: Golf Channel via Sling...

Your Samsung TV just got a personality – and it knows what you’re watching, what you need, and when to talk

Samsung’s new smart TVs now include the Vision AI CompanionThe conversational assistant is powered by Samsung Bixby, Microsoft Copilot, and PerplexityThe AI is angling...

What is the release date for Landman season 2 episode 1 on Paramount+?

I've been counting down the days for Landman season 2 after that explosive season 1 finale, and now the wait is finally over.As if...

Windows 11 users rebel as top Microsoft exec says operating system is ‘evolving into an agentic OS’

Pavan Davuluri, head of Windows at Microsoft, says that Windows 11 is "evolving into an agentic OS"There's been quite a negative reaction to this...

Valve’s new VR streaming trick won’t just work with its own headset

Valve’s new streaming-first VR headset — the Steam Frame — employs a clever trick to help make game streaming feel as low-latency as possible. It’s called...

Energy and tech news at UN climate negotiations in Brazil

Oxfam activists wearing oversized masks representing (L to R) European Commission President Ursula Von der Leyen, South Africa's President Cyril Ramaphosa, Argentina's President Javier...

The Steam Frame has two speakers on each side of your face for vibration cancellation

In its new Steam Frame VR headset, Valve put dual audio drivers on each side in the included head strap. That puts the audio...