Security researchers have identified two Unicode characters that can bypass display protections in Chromium-based browsers, enabling cybercriminals to register domain names that visually imitate legitimate websites while appearing as genuine URLs to users.
Cyberattacks leveraging lookalike domains—known as typosquatting—have long been a tactic for deceiving users into visiting malicious sites. However, advances in browser security have historically limited this practice. Recent discoveries, however, reveal new vulnerabilities in how browsers render certain Unicode characters.
According to Ian Muscat and Leanne Briffa of Have I Been Squatted, two specific characters—Ө (a Cyrillic letter common in Kazakh, Mongolian, and Tatar) and ƙ (a Latin letter used in Hausa and Karai-karai)—can effectively bypass Chromium’s security mechanisms. These characters visually mimic the Latin letters “e/o” and “k,” respectively, allowing attackers to create deceptive domains.
The researchers demonstrated this by registering 20 domains, such as аррӏө.com (mimicking “apple.com”) and sрасөх.com (mimicking “spasex.com”), which appear legitimate in Unicode but display as Punycode (e.g., xn--80a6aa68c8d.com) when rendered in raw form.
Chromium-based browsers deploy two primary defenses to combat such threats. First, a function called SafeToDisplayAsUnicode checks domains against a hardcoded list of Cyrillic characters known to mimic Latin letters. However, this system only blocks domains composed entirely of characters from the list. Characters like Ө, ї, and ү—termed “breakers”—are not included in the list, allowing mixed-character domains to bypass detection.
A second layer, GetSimilarTopDomain, compares domain skeletons (simplified versions stripping accents) against a list of ~8,500 popular sites. The Latin ƙ bypasses this check because it lacks diacritics, allowing domains like oƙta.com to evade scrutiny while appearing as “okta.com” to users.
The researchers emphasized that while protections like Chrome 148 have addressed certain breakers, these new vulnerabilities highlight ongoing gaps in browser security logic. Other Chromium versions may remain susceptible until updated defenses are implemented.
Additional measures, such as Safety Tips warnings, activate only for near-identical matches (exact, single-edit, or swapped letters). Domains with multiple alterations—like those using Ө—avoid these alerts, and shorter domains (under five characters) may bypass checks entirely.
Email clients also lack robust defenses; examples show Gmail rendering these domains in Unicode, while Outlook Web displays most in Punycode, inconsistent with their security risks.
Analyzing ICANN’s 167 million .com domains, the researchers found 162,000 internationalized domain names (IDNs) with ASCII-like counterparts. While some may serve legitimate purposes, organizations should monitor these vulnerabilities proactively.
Also Read
- 2026 Smart Scale Showdown: The Top Picks for Weight and Body Composition Tracking
- How Written Language Shapes the Pace of Cultural Evolution
- 2026 Singapore Grand Prix: Complete Viewing Guide for F1’s Historic Night Sprint Weekend
- Elon Musk escalates feud with Mukesh Ambani over Starlink’s India rollout


