Two lookalike letters evade Chromium checks in fake website addresses
Researchers found that two uncommon letters can be used to create website addresses that look genuine in Chromium-based browsers, including Chrome and Edge. The finding matters because users may trust a displayed address that resembles a popular site, even when the underlying domain is a fake.
The characters are Cyrillic ө and Latin ƙ, which resemble letters used in familiar web addresses. Researchers Ian Muscat and Leanne Briffa registered 20 lookalike domains and say the characters bypass Chromium’s Unicode display checks and its comparison against a list of nearly 8,500 popular domains. When those checks work, browsers show the less deceptive Punycode form; the article says the characters are absent from relevant protections in Chrome 154.
- Cyrillic ө and Latin ƙ can make fake domains look genuine in Chromium browsers.
- Researchers registered 20 lookalike domains that bypass browser checks.
- Chrome’s protections rely on character checks and comparisons with popular domains.
New here? Start with this
Website browsers include safety features designed to protect users from visiting fake websites that impersonate legitimate ones. Researchers have discovered that two uncommon characters, one from Cyrillic and one from Latin script, can evade these safety checks in Chrome and Edge browsers. This matters because people often trust the website address displayed in their browser to confirm they are visiting a legitimate site.
Ian Muscat and Leanne Briffa discovered this vulnerability by registering 20 fake domains using these lookalike characters. The characters closely resemble ordinary letters found in well-known website addresses, allowing them to bypass the browser's security systems. The problem affects Chrome 154 and other browsers built on the same underlying technology.
Browsers normally protect users in two ways: by comparing website addresses against a list of thousands of legitimate sites, and by checking for suspicious characters that might indicate a fake address. When these protections work correctly, the browser alerts the user to something amiss. However, these specific characters evaded both types of protection, potentially leaving users vulnerable to fraud.
Read the full article at the source →
Originally published by The Register as “Two characters open up a world of typosquatting opportunities in Chromium browsers”.