Chromium browsers face expanded typosquatting risk from two obscure characters

Two rare Cyrillic and Latin characters now enable simpler typosquatting attacks against popular sites in Chromium browsers.

The news

A report from The Register details how two specific characters create fresh opportunities for typosquatting in Chromium browsers. Attackers abuse rare Cyrillic and Latin letters to impersonate popular websites. The change lowers the barrier for domains that look legitimate to users while resolving to attacker-controlled addresses.

Context

Typosquatting has long relied on small spelling variations or look-alike characters. Prior techniques often required multiple substitutions or obvious homoglyphs that browser protections or careful inspection could catch. The new approach uses just two characters that differ only in subtle ways between Cyrillic and Latin scripts. This keeps the visual appearance close enough to fool quick glances yet registers as a distinct domain.

Chromium browsers handle internationalized domain names through punycode conversion. The two characters in question pass rendering checks that flag more obvious mismatches. Users typing or clicking links therefore see what appears to be the intended site until the connection lands elsewhere.

Details

The Register article focuses on the practical effect rather than naming the exact code points. It states that attackers are already registering variants that exploit the visual similarity. The technique works across Chromium-based browsers because the rendering engine treats the characters as valid within IDN labels. No additional browser configuration or extension is required for the impersonation to succeed.

The prior state relied on broader homoglyph sets that triggered more frequent warnings or failed visual matching in address bars. With only two characters now sufficient, the pool of available deceptive domains grows without needing complex scripts or multiple substitutions. The Register notes this opens opportunities specifically for impersonating high-traffic sites where users rarely examine every character.

No on-the-record quotes from vendors or researchers appear in the source. The piece limits itself to describing the character abuse and its effect on site impersonation. No numbers on registered domains or measured attack volume are provided.

Why it matters

Software engineers and site operators who rely on Chromium-based browsers for internal tools or customer traffic now face a narrower margin for visual domain checks. Standard punycode display and basic address-bar inspection no longer suffice when the difference rests on two rare letters. Teams that build or maintain login pages, password managers, or corporate portals should treat any unexpected domain variant as suspicious until proven otherwise.

The development also shifts defensive priorities. Blocking entire scripts or enforcing stricter IDN rules may reduce exposure, yet it risks breaking legitimate internationalized names. Organizations that previously accepted the status quo around homoglyph attacks will need to decide whether additional client-side validation or server-side allow-listing justifies the added friction.

For end users the change is invisible until a credential-harvesting site appears in search results or email links. The Register's reporting makes clear that the attack surface widened without any corresponding browser update or policy shift from the Chromium project itself.

---

Sources:

No comments yet