Researchers demonstrate how two specific glyphs can bypass Chromium's safety checks and display spoofed domains as if they were real.
The attack exploits non-ASCII characters that resemble common Latin letters and incomplete bypasses in browser defenses.
The finding highlights ongoing limits in browser spoofing defenses and how users can stay vigilant.
Quick read · 1 min
Two Unicode glyphs can trick Chromium browsers into showing lookalike domains as real addresses. The risk comes from characters not fully covered by safety checks in Chrome and Edge. Browsers also rely on a skeleton check against popular sites, which can miss some breakers. What this means for you is simple: be cautious with unfamiliar links and use trusted bookmarks. Expect tighter browser protections in the near future, but don’t wait to act, enable two‑factor authentication and verify addresses before entering credentials.
What to do now:
Favor bookmarks for sites you visit often.
Don’t click links from unknown emails or messages if the domain looks unusual.
Enable two‑factor authentication on core accounts.
Two characters can quietly break the way Chromium-based browsers decide what looks safe to display. In a new demonstration, researchers showed that certain non‑ASCII glyphs can make lookalike domains appear authentic in Chrome, Edge and other Chromium browsers. The problem is not just a quirky bug; it’s a real phishing vector that could trick ordinary users into visiting fake sites that resemble real brands.
The researchers from Have I Been Squatted tested glyphs that aren’t common in ASCII: ө and ƙ, alongside a few others. When these characters slip into a domain name, they can resemble letters like e, o, i and k to the human eye, but they’re not the same characters the browser uses for safety checks. The combined effect can bypass Chromium’s seven‑check safety net that’s meant to catch spoofed domains and show them in Punycode instead of the familiar looking address.
To make this concrete, the demo domains used lookalikes such as arcane strings that, when displayed, appear almost identical to real sites but actually route to harmless demo pages set up by the researchers. The key point is that some of these glyphs simply aren’t included in Chromium’s hardcoded “spoofing” list, so one or more checks don’t trigger. When the checks fail, the browser may display a fake URL that looks trustworthy to a casual glance.
Chromium does have a second defense: a function that builds a “skeleton” of the domain to compare it against a list of about 8,500 popular sites. The idea is to catch near‑matches that could mislead users. But the researchers found the characters in question can still slip past this skeleton check because the glyphs are treated as different letters in the skeleton path. The result is a warning gap that could be exploited in the wild.
Safety tips remain in place as a final line of defense. Browsers will sometimes warn you if the domain looks fake or if a substitution seems suspicious. But those warnings have limits too. If the domain is only slightly altered or uses a short string, the browser might not raise an alert. And if a user does not have a history of visiting the genuine site, the warning logic may not trigger at all.
In practice, what this means for everyday users is simple: phishing and impostor domains are not going away, and there are new, subtle ways attackers could try to slip a fake site past you. Keeping a sharp eye on the address bar, avoiding clicking through from unfamiliar links, and using multi‑factor authentication where available remain wise steps. If you ever see a domain that looks off, even slightly, trust your instincts and type the site address manually or use a trusted bookmark.
Ultimately, this isn’t a Chrome problem alone. It’s a reminder that phishing lures evolve with language and script. Browser vendors will likely respond with tighter checks or new warnings, but users still need to stay vigilant, especially on sites that request login credentials or payment details.
01
What is typosquatting and why now
Typosquatting is when attackers leverage domain names that resemble real brands to confuse people. The novelty here is using characters that look the same to the eye but aren’t the same code points the browser uses to verify safety. That mismatch lets spoofed domains pass past certain defenses and appear legitimate at a glance.
02
Which browsers could be affected
The demonstration centers on Chromium‑based browsers, which include Google Chrome and Microsoft Edge. Any browser built on the Chromium engine that borrows similar display safeguards could be affected in the same way if it relies on the same two defense layers.
03
What this means for you
For most readers, this is a reminder to be careful about brand or login pages you reach through unusual links. If you see a site that claims to be a familiar brand but the URL looks off or uses unusual characters, don’t enter credentials. Use your saved bookmarks or manually type the address you know is correct. Enabling two‑factor authentication where available also adds a critical layer of protection.
04
What happens next
Browser makers will likely refine their Unicode handling and ad‑hoc checks to cover more breakers in the future. In the meantime, stay cautious and rely on trusted addresses. If you manage a business or run a newsletter, consider advising users to double‑check any login pages that come via email or newer social posts, especially if the link looks slightly odd.
Yes, the researchers demonstrated domains that appeared legitimate but aren’t. Practical risk depends on whether you encounter such a spoof during an actual phishing attempt.
What should I do to stay safe?
Stick to bookmarks or manually type known good addresses, be wary of suspicious links, and enable two‑factor authentication on important accounts.
A Ukrainian drone strike damaged a huge Yandex data center in Kaluga, knocking several modules offline and signaling renewed pressure on Russia’s cloud backbone.
A one-time payment of $14.97 gets AdGuard’s Family Plan for up to nine devices, with ad blocking, privacy protection, malware protection, and parental controls through Oct. 11.
A Vancouver startup’s new helmet design uses modular foam sections to reduce both direct and rotational head impacts, earning top marks in Virginia Tech’s STAR ratings.
4 min read
We use cookies to understand how readers use Talk With Tech, so we can make it better. Is that OK? Privacy policy
The Daily Brief
Today's biggest tech stories, in 5 minutes
Every morning, the news that matters from AI, phones, apps and the people shaping tech. Explained in plain English. Free.
One email a day. No spam, unsubscribe anytime. Privacy policy