---
id: "6100765d-944a-4698-b1a7-416a2e8ad7ff"
kind: "link"
title: "Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers"
language: "en"
section: "security"
date: "2026-10-11T14:01:28Z"
updated: "2026-10-11T14:01:28Z"
canonical: "https://tldlog.com/l/rare-cyrillic-latin-letters-let-attackers-spoof-urls/"
origin: "master"
translations:
  es: "https://tldlog.com/es/l/letras-raras-cirilicas-latinas-permiten-falsificar-url/"
  de: "https://tldlog.com/de/l/seltene-kyrillische-lateinische-buchstaben-taeuschen-urls/"
  fr: "https://tldlog.com/fr/l/lettres-cyrilliques-latines-rares-permettent-usurpation-url/"
  it: "https://tldlog.com/it/l/lettere-cirilliche-latine-rare-permettono-falsificare-url/"
  pt-BR: "https://tldlog.com/pt/l/letras-raras-cirilicas-latinas-permitem-falsificar-urls/"
  ru: "https://tldlog.com/ru/l/redkie-kirillicheskie-latinskie-bukvy-pozvolyayut-poddelyvat/"
  zh-Hans: "https://tldlog.com/zh/l/rare-cyrillic-latin-letters-let-attackers-spoof-urls/"
source:
  name: "theregister.com"
  url: "https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383"
  language: "en-US"
  date: "2026-10-10T10:15:00Z"
---

# Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers

## in plain words

Chrome and Edge are built to stop scammers from registering fake web addresses that look like real brand names. Security researchers found two unusual letters, from Cyrillic and Hausa alphabets, that slip past those protections. This means a fake address can look exactly like a real one, such as apple.com or nike.com, which could trick people into visiting phishing sites.

Security researchers Ian Muscat and Leanne Briffa of Have I Been Squatted identified two characters that can defeat Chromium’s defenses against typosquatting: the Cyrillic barred o, ө, used in Kazakh, Mongolian and Tatar, and the Latin K with hook, ƙ, used in Hausa and Karai-karai. Both closely resemble Latin letters o/e and k, letting the pair register 20 convincing lookalike domains, including versions mimicking apple.com, spacex.com, okta.com and nike.com, all of which remain registered as safe demonstration pages.

Chromium browsers normally rely on two defenses. The first, a function called SafeToDisplayAsUnicode, runs seven checks against a hardcoded list of Cyrillic characters known to mimic Latin letters, but only blocks a domain if every character in the string appears on that list. Because ө and similar letters are absent from the list as of Chrome 154, released September 22, their presence lets a lookalike string pass undetected, a flaw the researchers call a “breaker.”

The second defense, GetSimilarTopDomain, strips diacritics from a domain to form a simplified “skeleton” and compares it against roughly 8,500 popular domains. If the skeleton matches, the browser forces Punycode display to expose the fraud. But ƙ has no accent to strip, so it is converted into a Latin k plus a combining mark, producing a skeleton that fails to match the real domain, such as okta.com rendering as a different skeleton string. The Cyrillic barred o behaves similarly, keeping its bar as a combining mark so its skeleton never lines up with the genuine Apple domain.

These flaws build on a history of similar bypasses, including Xudong Zheng’s 2017 registration of an all-Cyrillic apple.com lookalike, which prompted vendors to add the current checks. Browser makers have continued patching related issues, with Chrome 148 closing an earlier bypass method.

Source: [theregister.com](https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383)
