Two characters slip past Chromium typosquatting defences

Cyrillic ө and Latin ƙ let researchers register lookalike domains that display as genuine addresses in Chrome and Edge

By LineZotpaper
Published
Read Time2 min
Security researchers have identified two characters that bypass the protections Chromium-based browsers use to expose lookalike websites, allowing fake URLs to appear as genuine web addresses. Ian Muscat and Leanne Briffa of Have I Been Squatted registered 20 lookalike domain names to demonstrate the flaw, which defeats the key security measures deployed by Chromium browsers.

Typosquatting, the practice of registering domain names that resemble popular websites, is a familiar phishing technique. Attackers have long used sites such as macrosoft[.]com and applle[.]com to trick users. The new work shows that gaps remain in the defences browsers built to reveal such spoofs.

The two characters of note are ө, found in Cyrillic languages including Kazakh, Mongolian and Tatar, and the Latin K with hook, ƙ, used in Hausa. Both are visually similar to the letters e, o, i and k. The researchers registered 20 lookalike domain names using them, including aррӏө[.]com, sрасөх[.]com, oƙta[.]com and niƙe[.]com. The domains are registered by Have I Been Squatted, are safe to visit, and lead to research pages explaining the bypass.

Chromium browsers deploy two main defence layers. The first, the SafeToDisplayAsUnicode function, runs a set of seven checks introduced in 2017 after researcher Xudong Zheng registered аррӏе.com, a domain made entirely of Cyrillic characters. The checks are "all or nothing": they only act if every character in a domain is on a hardcoded list of known lookalike Cyrillic characters. Characters such as ө, ї and ү, described as "breakers", are absent from the list as of Chrome 154, released to the stable channel on September 22.

The second layer, the GetSimilarTopDomain() function, converts a domain into a "skeleton", stripping diacritics such as accents, and compares it against a hardcoded list of almost 8,500 popular websites. The Latin K with hook has no accent, so the conversion produces a Latin k with an added combining mark, evading the check. The Cyrillic barred o in аррӏө.com likewise retains its bar in the skeleton as a combining mark.

The result is that affected domains display in Unicode, looking like genuine addresses, while their Punycode forms, which would reveal how different they are from the real sites, are never shown.

§

Analysis

Why This Matters

  • The address bar is a primary trust signal in web browsing; lookalike domains that pass display checks can steer users to phishing pages and credential theft.
  • Chrome and Edge are two of the most widely used browsers and share the same Chromium code base, so the bypass affects a large share of web users.
  • The researchers registered the domains themselves, but the same technique is available to attackers, who could point lookalike domains at malicious sites.

Background

Typosquatting is a long-standing form of phishing in which attackers register names such as macrosoft[.]com or applle[.]com that closely resemble popular destinations. Chromium's current defences date back to 2017, when the all-Cyrillic аррӏе.com demonstration prompted the seven display checks. The limitations reflect a trade-off: checks and lists must be narrow enough not to break legitimate domains that use non-Latin scripts, which leaves room for characters that sit outside the known lookalike lists.

Key Perspectives

Have I Been Squatted researchers: They registered the 20 lookalike domains as safe demonstration sites and published pages explaining the bypasses, aiming to document weaknesses in browser protections before they are exploited in the wild. Browser vendors (Google and Microsoft): They maintain Chromium's hardcoded character lists and skeleton checks, and update them over time. The "all or nothing" design reflects the difficulty of flagging spoofs without penalising legitimate multilingual domains. Critics and skeptics: The bypass depends on relatively obscure characters that may not apply to every user or language, and the affected sites only remain disguised while the checks fail to trigger. Browsers could close the gap with targeted list updates, though new characters may create fresh holes as Unicode support expands.

What to Watch

  • Whether Google and Microsoft update Chromium's hardcoded lookalike lists and skeleton logic in a future release.
  • Whether the researchers' disclosure leads to a formal fix in Chrome and Edge, and how quickly it reaches stable channels.
  • Whether similar display bypasses are found in other browsers, such as Firefox and Safari, which use their own defences.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe