Serious vulnerabilities with OpenPGP and S/MIME
In a nutshell, EFAIL abuses active content of HTML emails, for example externally loaded images or styles, to exfiltrate plaintext through requested URLs."
The EFF recommends
uninstalling email-encryption tools that automatically
decrypt email entirely. "Until the flaws
described in the paper are more widely understood and fixed, users should
arrange for the use of alternative end-to-end secure channels, such as
Signal, and temporarily stop sending and especially reading PGP-encrypted
email.
"
