Ethical Hacking News
Researchers have discovered that two specific characters, ө and ƙ, can be used to trick Chromium browsers into displaying lookalike URLs as genuine web addresses, thereby exposing users to phishing and typosquatting attacks. This vulnerability highlights the need for browsers and users to be aware of the potential risks of typosquatting and to take steps to protect themselves.
Researchers have discovered that using specific characters (ө and ƙ) can bypass security measures in Chromium-based browsers, allowing typosquatters to create fake domains.These characters can be used to trick Chromium browsers into displaying lookalike URLs as genuine web addresses.The vulnerabilities can be bypassed by the SafeToDisplayAsUnicode function, which checks for rare Cyrillic and Latin letters.The GetSimilarTopDomain function can also be bypassed by the Latin K with hook (ƙ) character.Certain Chromium browser versions (including Chrome 148) have been patched to prevent similar vulnerabilities, but ө and ƙ can bypass these patches.Users are advised to use strong passwords, be cautious when clicking on links from unknown sources, and keep their browsers up-to-date to prevent typosquatting attacks.
Typosquatters, a group of malicious individuals who aim to steal sensitive information by creating fake websites that resemble genuine ones, have found a new way to bypass the security measures of Chromium-based browsers. Researchers have discovered that two specific characters, ө and ƙ, can be used to trick Chromium browsers into displaying lookalike URLs as genuine web addresses, thereby exposing users to phishing and typosquatting attacks.
The use of these characters, which are found in various Cyrillic and Latin languages, was first identified by Ian Muscat and Leanne Briffa of Have I Been Squatted, a cybersecurity organization that tracks and exposes typosquatted domains. The researchers discovered that these characters can be used to create a range of fake domains, including arpӏe.com, srasөх.com, and oƙta.com, which can bypass the security checks of Chromium browsers.
The security measures deployed by Chromium browsers, which include two main defense layers, are designed to prevent typosquatters from creating fake domains that resemble genuine ones. The first layer, known as SafeToDisplayAsUnicode, checks for a range of common spoofing methods, including the use of rare Cyrillic and Latin letters. The second layer, known as GetSimilarTopDomain, compares the domain name against a list of popular websites to see if it is trying to imitate one of them.
However, the use of the characters ө and ƙ can bypass these security checks. The SafeToDisplayAsUnicode function, which is designed to detect all-Cyrillic strings, can be fooled by the presence of these characters, which are not on its hardcoded list. This means that if one character is missing from the list, the check is bypassed, allowing the typosquatter to create a fake domain that appears to be genuine.
The GetSimilarTopDomain function, which is designed to compare the domain name against a list of popular websites, can also be bypassed by the use of the Latin K with hook, ƙ. This character, which is not on the list of popular websites, allows the typosquatter to create a fake domain that resembles a genuine one, even if it does not contain the same characters.
The researchers also found that some Chromium browsers, including Chrome 148, have been patched to prevent the use of certain characters, such as ҏ and ӿ, which are known to be "breakers" and can bypass the security checks. However, the use of the characters ө and ƙ can bypass these patches, allowing typosquatters to create fake domains that are difficult to detect.
The discovery of these vulnerabilities highlights the need for browsers to continually update and improve their security measures to prevent typosquatters from creating fake domains that expose users to phishing and typosquatting attacks. The use of rare Cyrillic and Latin letters, which can bypass the security checks of Chromium browsers, is a new front in the war against typosquatting, and it is essential that browsers and users are aware of these vulnerabilities and take steps to prevent them.
In addition to the vulnerabilities in Chromium browsers, researchers have also found that some browsers, including Firefox, can be tricked into displaying fake domains as genuine web addresses. This can occur when a typosquatter creates a fake domain that is similar to a genuine one, but contains a different character or two characters.
The discovery of these vulnerabilities highlights the need for browsers to continually update and improve their security measures to prevent typosquatters from creating fake domains that expose users to phishing and typosquatting attacks. It also highlights the need for users to be aware of the potential risks of typosquatting and to take steps to protect themselves, such as using strong passwords and being cautious when clicking on links from unknown sources.
In conclusion, the discovery of the vulnerabilities in Chromium browsers highlights the need for browsers and users to be aware of the potential risks of typosquatting and to take steps to protect themselves. The use of rare Cyrillic and Latin letters, which can bypass the security checks of Chromium browsers, is a new front in the war against typosquatting, and it is essential that browsers and users are aware of these vulnerabilities and take steps to prevent them.
Related Information:
https://www.ethicalhackingnews.com/articles/Exploiting-the-Vulnerabilities-of-Chromium-Browsers-A-New-Front-in-the-War-Against-Typosquatting-ehn.shtml
https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383
Published: Sat Oct 10 06:29:55 2026 by llama3.2 3B Q4_K_M