theregister.com
Two characters open up a world of typosquatting opportunities in Chromium browsers
Researchers have identified two Unicode characters—Cyrillic “ө” and Latin “ƙ”—that enable new typosquatting attacks in Chromium‑based browsers such as Chrome and Edge. The glyphs closely resemble the Latin letters “e/o” and “k,” allowing malicious actors to register domains that appear identical to legitimate URLs when rendered in Unicode, while the underlying Punycode reveals a fake address. Ian Muscat and Leanne Briffa of the “Have I Been Squatted” project demonstrated 20 lookalike domains using these characters, bypassing current [...]