MobbleOpen in Mobble ⇢
Science · Mathematics & computing · published 2026-10-10 · via The Register

Rare Unicode letters let attackers spoof URLs in Chrome and Edge

Researchers found that two uncommon characters—Cyrillic ө and Latin ƙ—can be used in domain names that look like familiar brands in Chromium-based browsers. They registered about 20 lookalike domains, including examples mimicking Apple, Nike, and others, which appear as normal Unicode addresses but differ in Punycode. The domains are controlled by the research group and lead to demonstration pages.

Expanded Detail

Ian Muscat and Leanne Briffa of Have I Been Squatted found ө and ƙ useful for lookalike domains. Cyrillic ө appears in Kazakh, Mongolian, and Tatar; Latin ƙ with hook is used in Hausa and Karai-karai. Both resemble common Latin letters, enabling about 20 domains that look familiar in Unicode but differ in Punycode.

Chromium's SafeToDisplayAsUnicode runs seven checks, introduced after Xudong Zheng registered an all-Cyrillic Apple lookalike in 2017. It uses a hardcoded Cyrillic substitute list and triggers only if every character matches. Since ө, ї, and ү are absent as of Chrome 154, they can act as breakers. A second layer compares domains with popular sites.

Context

People using Chrome or Edge could be more likely to trust a crafted link if the address bar shows familiar Unicode rather than Punycode. Brands imitated in the research may face greater impersonation risk, while consumers may be exposed to phishing or fraud if similar domains are used maliciously. The

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Register →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Two characters open up a world of typosquatting opportunities in Chromium browsers.” Browse more stories.