Researchers Identified New Chromium URL Spoofing Methods

Security researchers discovered two Unicode characters that bypass existing browser defenses to mask malicious domain names.

Updated on Oct. 10, 2026 in Cybersecurity

Isometric editorial illustration of industrial metal links and glowing geometric spheres representing digital domain trust pathways.
Security researchers have discovered a Chromium browser vulnerability using specific Unicode characters that allows malicious domain names to bypass spoofing protections. AI Illustration. Upload story photo >

Live Poll

Do you trust that the web addresses displayed in your browser are always the genuine sites?

Security researchers have identified two specific Unicode characters that allow attackers to bypass Chromium browser security checks, causing lookalike URLs to render in plain text instead of safer formats. The vulnerability currently affects how platforms like Gmail display domain names.

Why it matters

The flaw demonstrates how evolving Internationalized Domain Names can bypass browser spoofing protections, potentially exposing users to sophisticated phishing attacks. This research highlights the challenges of maintaining secure domain rendering across an increasingly complex global web.

Chromium browsers utilize seven sequential checks within the SafeToDisplayAsUnicode function to detect potential spoofing. Researchers successfully bypassed these protections because specific characters, such as the Kazakh-used ө, are omitted from the browser's hardcoded lookalike list.

The players

Chromium

An open-source browser project that serves as the foundation for the majority of modern web browsers including Chrome and Edge.

The details

The vulnerability exploits a logic gap in how browsers process non-ASCII characters. Chromium uses the GetSimilarTopDomain function to compare URLs against a list of 8,500 popular websites; however, the researchers found that using the character ƙ allows a domain to bypass this check as it is processed as a Latin k with a combining mark. This allows malicious URLs to appear legitimate rather than being converted into Punycode, a system that represents Unicode characters as ASCII, which would alert users to the spoofing attempt.

Timeline

  1. 2017: Vendors began introducing seven sequential display checks.

  2. September 22, 2026: Chrome 154 was released to the stable channel.

  3. October 10, 2026: The research report on typosquatting was published.

The Tech Race

This research directly challenges the efficacy of existing browser-side spoofing defenses against the rising number of Internationalized Domain Names. It highlights an ongoing race between attackers leveraging non-standard characters and the manual, hardcoded lists maintained by browser vendors.

Users may encounter lookalike URLs that display as plain text rather than the safer Punycode format, increasing the risk of credential theft on services like Gmail. There is currently no user-facing fix for this, and security updates for browser rendering logic are expected to follow in future releases.

The takeaway

The research serves as a reminder that browser security relies on brittle, manual lists of characters that struggle to keep pace with the expansion of global domain names. Users should monitor for future browser updates that address this character-list vulnerability as the primary method for containment.

Further reading

For broader context on browser defense mechanisms, explore the Cybersecurity section.

Source note: This article includes information reported by TheRegister.

Live Poll

Do you trust that the web addresses displayed in your browser are always the genuine sites?