Skip to main content
CybersecurityHacking

Typosquatters Exploit Chromium Browser Flaw with Two Characters

Laptop screen with suspicious URL in cluttered workspace near window with natural light.

"They all bypass the key security measures deployed by Chromium-based browsers." That blunt finding comes from researchers Ian Muscat and Leanne Briffa of Have I Been Squatted, who demonstrate how two little-known characters can reliably trick Chromium into showing lookalike URLs as legitimate addresses.

Two small characters, a big imitation problem

The characters at the centre of the research are the Cyrillic barred o (ө) and the Latin K with hook (ƙ). Both are visually similar to common Latin letters — ө to e/o/i variants in some fonts, and ƙ to k — and the researchers used them to register 20 lookalike domains. Examples supplied by Have I Been Squatted include aррӏө[.]com, sрасөх[.]com, oƙta[.]com and niƙe[.]com. Their Punycode equivalents, which is how browsers should display them when treating them as unsafe, are xn--80a6aa68c8d.com, xn--80a5aeq0fr0c.com, xn--ota-f6a.com and xn--nie-g6a.com.

How Chromium's two main defenses are sidestepped

Chromium uses two principal layers to decide whether to show a domain in Unicode or to reveal its Punycode. The first is SafeToDisplayAsUnicode, which runs seven sequential checks and relies on a hardcoded list of Cyrillic characters used historically in spoofing. That approach is effectively "all or nothing": if every character in a domain is on the list, the browser takes action; if even one is missing, the check can be bypassed. Researchers call characters that are not on the lookalike list "breakers" — ө, ї and ү are named examples — and Chrome 154 (released to the stable channel on September 22) still omits some of those breakers from its hardcoded list.

The second defensive step is GetSimilarTopDomain(), which converts a domain into a "skeleton" by stripping diacritics and then comparing that skeleton against a hardcoded list of almost 8,500 popular websites. If the skeleton matches, the browser shows Punycode. But the Latin K with hook, ƙ, does not decompose into a plain k in the skeleton check; instead it is added as a Latin k with an added combining mark, producing a skeleton that does not match the genuine domain. For example, the researchers show oƙta[.]com forming a skeleton that maps as [o k ‘ t a . c o r n], and aррӏө[.]com maps as [a p p l o - . c o r n], neither matching the intended targets.

Safety Tips, one-edit rules, and practical blind spots

Chromium also deploys navigation-time "Safety Tips" — popups that warn users if a visited domain appears to imitate a popular site. Those warnings trigger for exact-character matches, one-edit matches, or adjacent swaps, and they also consider the skeleton against sites users visit frequently. But they do not catch multi-character substitutions or domains shorter than five characters. The researchers use ínstagarm[.]com as an example where warnings may fire; by contrast, domains such as aррӏө[.]com have multiple substitutions and will not trigger Safety Tips. The one-edit rule may leave small domains like oƙta.com (four characters, and one edit from Okta) outside those defenses for many users, and the Safety Tips behavior depends in part on a user's visit history.

Email clients, measurements, and the scope of lookalikes

These checks apply only to browsers. Have I Been Squatted found that Gmail displayed each of the 20 domains they tested — a mix of lookalikes and genuine internationalized domain names (IDNs) — in Unicode, meaning end users saw the characters as the international letters rather than the Punycode form. Outlook Web, by contrast, showed all 20 domains as Punycode, including benign ones, indicating varying client behaviour rather than a single correct approach.

To quantify how many .com domains could yield lookalikes, the researchers analysed ICANN’s .com list. There are roughly 167 million .com domains, about 733,000 of which are IDNs (domains containing non-ASCII characters and stored as Punycode). By mapping each IDN to ASCII equivalents, the team identified about 162,000 pairs of IDN-to-ASCII resemblances. The researchers were careful to note that such pairs are not synonymous with active typosquats: some lookalikes may be defensive registrations or legitimate multilingual sites owned by the same entity. Still, the number underlines the scale of potential confusability.

What this means for technologists, browser vendors, and enterprises

  • Technologists and security teams: Monitor registered domains and consider scanning for IDN-to-ASCII pairs — the researchers’ method found about 162,000 resembles in the .com space — and treat live lookalikes as potential risks even when Punycode is not immediately displayed.
  • Browser vendors: Chromium's SafeToDisplayAsUnicode and GetSimilarTopDomain routines both rely on hardcoded lists and decomposition rules; the researchers highlight how characters that act as "breakers" slip through, and historical fixes (Chrome 148 removed ҏ and ӿ as breakers) show vendors can respond with targeted changes.
  • Enterprises and end users: Email clients and webmail differ in behavior; Gmail showed the 20 test domains in Unicode while Outlook Web displayed Punycode. Relying on client-side display alone is risky, especially for short domains or domains with multiple substitutions that will not trigger Safety Tips.

Have I Been Squatted hosted the demo pages themselves and invites inspection: the registered lookalikes are safe to visit and include explanations of how each bypass works. The larger takeaway is a narrow technical fact with broad consequence: when display logic treats a single character differently, it can turn a tiny typographic choice into an effective camouflage. Browser safeguards have evolved, but the research underlines that the surface for impersonation is still shifting — and that defenders who presume Unicode display equals safety may be looking at a mirage.

https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383