VYPR
researchPublished Oct 10, 2026· 1 source

Cyrillic and Latin Characters Enable Sophisticated Typosquatting in Chromium Browsers

Researchers have identified two characters, Cyrillic 'ө' and Latin 'ƙ', that can bypass Chromium browser defenses, enabling visually identical lookalike URLs for phishing and typosquatting attacks.

Security researchers have uncovered a significant vulnerability in Chromium-based browsers, including Google Chrome and Microsoft Edge, that allows for sophisticated typosquatting and phishing attacks. The flaw lies in the browser's handling of specific non-ASCII characters, namely the Cyrillic 'ө' and the Latin 'ƙ' with a hook. These characters can be used to create domain names that appear identical to legitimate URLs, even when the underlying Punycode representation clearly indicates a different domain.

These newly identified characters bypass two critical browser security mechanisms: SafeToDisplayAsUnicode and GetSimilarTopDomain. SafeToDisplayAsUnicode is designed to detect and flag common spoofing methods, particularly those involving Cyrillic characters that mimic Latin letters. However, the Cyrillic 'ө' acts as a 'breaker' character, not being present on the hardcoded list of known Cyrillic characters used in spoofing. This allows it to evade the initial seven-step check, preventing the browser from defaulting to displaying the Punycode representation.

The second layer of defense, GetSimilarTopDomain, attempts to identify domains that are visually similar to popular websites by converting them into a 'skeleton' format. This process strips diacritics and other modifying marks. While effective against many homoglyphs, the Latin 'ƙ' bypasses this check because it does not have a diacritic and is added to the skeleton with a combining mark, which is not recognized as a modification that would alter its similarity to a standard Latin 'k'. This allows domains like 'okta.com' to be mimicked by 'oƙta.com' without triggering alerts.

Researchers from Have I Been Squatted demonstrated this by registering 20 lookalike domain names using these characters. Examples include 'аррӏө.com' (mimicking Apple) and 'oƙta.com' (mimicking Okta). These domains, when viewed in Unicode, appear legitimate, but their Punycode equivalents, such as 'xn--80a6aa68c8d.com' and 'xn--ota-f6a.com', reveal their deceptive nature. The researchers have made these domains publicly accessible, leading to demo pages that explain the bypasses in detail.

While Chromium employs additional defenses like Safety Tips, which warn users of potentially fake domains, these too have limitations. These warnings typically trigger for exact-character matches, one-edit distance matches, or adjacent character swaps. Domains with multiple character substitutions, like 'аррӏө.com', or those with fewer than five characters, such as 'oƙta.com', may not trigger these warnings, leaving users vulnerable.

The implications of this discovery are significant for cybersecurity. Typosquatting and phishing attacks can be made far more convincing, potentially leading to widespread credential theft, malware distribution, and financial fraud. The ability to bypass established browser defenses means that even vigilant users could be tricked into visiting malicious sites.

This vulnerability highlights the ongoing cat-and-mouse game between browser developers and malicious actors. As browsers update their defenses to counter known spoofing techniques, attackers continuously find new characters and encoding tricks to exploit. The researchers emphasize that email clients are often even less discerning than browsers, suggesting that similar attacks could be even more prevalent in email-based phishing campaigns.

Users are advised to exercise extreme caution when navigating to unfamiliar websites, always double-checking the URL for any subtle discrepancies, especially when dealing with sensitive transactions or personal information. The ongoing research into these character-based bypasses underscores the need for continuous vigilance and updates to browser security protocols.

Synthesized by Vypr AI