Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers
in plain words
Chrome and Edge are built to stop scammers from registering fake web addresses that look like real brand names. Security researchers found two unusual letters, from Cyrillic and Hausa alphabets, that slip past those protections. This means a fake address can look exactly like a real one, such as apple.com or nike.com, which could trick people into visiting phishing Impersonating a trusted party to steal data, often with look-alike domains. Full definition of phishing sites.
Security researchers Ian Muscat and Leanne Briffa of Have I Been Squatted identified two characters that can defeat Chromium’s defenses against typosquatting Registering misspellings of well-known names to catch typing mistakes. Full definition of typosquatting: the Cyrillic barred o, ө, used in Kazakh, Mongolian and Tatar, and the Latin K with hook, ƙ, used in Hausa and Karai-karai. Both closely resemble Latin letters o/e and k, letting the pair register 20 convincing lookalike domain A domain designed to be mistaken for that of a known brand or organization. Full definition of lookalike domain, including versions mimicking apple.com, spacex.com, okta.com and nike.com, all of which remain registered as safe demonstration pages.
Chromium browsers normally rely on two defenses. The first, a function called SafeToDisplayAsUnicode, runs seven checks against a hardcoded list of Cyrillic characters known to mimic Latin letters, but only blocks a domain if every character in the string appears on that list. Because ө and similar letters are absent from the list as of Chrome 154, released September 22, their presence lets a lookalike string pass undetected, a flaw the researchers call a “breaker.”
The second defense, GetSimilarTopDomain, strips diacritics from a domain to form a simplified “skeleton” and compares it against roughly 8,500 popular domains. If the skeleton matches, the browser forces Punycode The encoding that turns internationalized domain names into ASCII starting with xn--. Full definition of Punycode display to expose the fraud. But ƙ has no accent to strip, so it is converted into a Latin k plus a combining mark, producing a skeleton that fails to match the real domain, such as okta.com rendering as a different skeleton string. The Cyrillic barred o behaves similarly, keeping its bar as a combining mark so its skeleton never lines up with the genuine Apple domain.
These flaws build on a history of similar bypasses, including Xudong Zheng’s 2017 registration Obtaining the right to use a domain name for a set period. Full definition of registration of an all-Cyrillic apple.com lookalike, which prompted vendors to add the current checks. Browser makers have continued patching related issues, with Chrome 148 closing an earlier bypass method.