Typosquatting, the practice of registering domain names that resemble popular websites, is a familiar phishing technique. Attackers have long used sites such as macrosoft[.]com and applle[.]com to trick users. The new work shows that gaps remain in the defences browsers built to reveal such spoofs.
The two characters of note are ө, found in Cyrillic languages including Kazakh, Mongolian and Tatar, and the Latin K with hook, ƙ, used in Hausa. Both are visually similar to the letters e, o, i and k. The researchers registered 20 lookalike domain names using them, including aррӏө[.]com, sрасөх[.]com, oƙta[.]com and niƙe[.]com. The domains are registered by Have I Been Squatted, are safe to visit, and lead to research pages explaining the bypass.
Chromium browsers deploy two main defence layers. The first, the SafeToDisplayAsUnicode function, runs a set of seven checks introduced in 2017 after researcher Xudong Zheng registered аррӏе.com, a domain made entirely of Cyrillic characters. The checks are "all or nothing": they only act if every character in a domain is on a hardcoded list of known lookalike Cyrillic characters. Characters such as ө, ї and ү, described as "breakers", are absent from the list as of Chrome 154, released to the stable channel on September 22.
The second layer, the GetSimilarTopDomain() function, converts a domain into a "skeleton", stripping diacritics such as accents, and compares it against a hardcoded list of almost 8,500 popular websites. The Latin K with hook has no accent, so the conversion produces a Latin k with an added combining mark, evading the check. The Cyrillic barred o in аррӏө.com likewise retains its bar in the skeleton as a combining mark.
The result is that affected domains display in Unicode, looking like genuine addresses, while their Punycode forms, which would reveal how different they are from the real sites, are never shown.