New Unicode characters let attackers spoof URLs in Chromium browsers
Researchers identified two non-ASCII characters that bypass Chromium’s safety checks, letting malicious sites appear as legitimate URLs.
A study by Ian Muscat and Leanne Briffa of Have I Been Squatted reveals that two characters—Cyrillic ө and Latin ƙ—can be exploited to create deceptive domain names that Chromium-based browsers display as Unicode, masking their true Punycode form. By registering domains like aррӏө.com and oƙta.com, the researchers showed that these names slip past the seven sequential checks in Chrome’s SafeToDisplayAsUnicode function and the GetSimilarTopDomain similarity algorithm.
The bypass works because the characters are not on the hard-coded list of known look-alikes, allowing the skeleton comparison to miss the spoof. While Chrome’s Safety Tips can warn users for simple edits, they fail for multi-character changes or short domains, leaving users vulnerable. The authors also surveyed ICANN’s.com registry, finding roughly 162,000 IDN-ASCII pairs that could be used for typosquatting, underscoring the scale of the threat. They advise organizations to monitor domain registrations and consider the new homograph risks when assessing phishing defenses.
Why it matters
The findings expose a loophole that could let phishing sites trick users of Chrome and Edge, increasing online fraud risk.
In this story
