Two characters open up a world of typosquatting opportunities in Chromium browsers
theregister.com Oct 10, 2026

Two characters open up a world of typosquatting opportunities in Chromium browsers

AI-summarised brief · reviewed before publication

Researchers have identified two Unicode characters—Cyrillic “ө” and Latin “ƙ”—that enable new typosquatting attacks in Chromium‑based browsers such as Chrome and Edge. The glyphs closely resemble the Latin letters “e/o” and “k,” allowing malicious actors to register domains that appear identical to legitimate URLs when rendered in Unicode, while the underlying Punycode reveals a fake address. Ian Muscat and Leanne Briffa of the “Have I Been Squatted” project demonstrated 20 lookalike domains using these characters, bypassing current browser safety checks that rely on visual similarity detection. The findings highlight a gap in how browsers display internationalized domain names, exposing users to phishing sites that can masquerade as popular services without triggering standard warnings.

💡 Why It Matters

  • · Attackers can now exploit obscure characters to craft convincing phishing URLs that slip past existing browser defenses, increasing the risk of credential theft.