Two characters open up a world of typosquatting opportunities in Chromium browsers
First reported by The Register ·
Users of Chromium browsers may be tricked into visiting malicious sites that look like legitimate URLs.
Researchers Ian Muscat and Leanne Briffa from Have I Been Squatted have identified a new method for typosquatting that circumvents security checks in Chromium-based browsers like Chrome and Edge. Attackers can use specific Cyrillic and Latin characters, such as the Cyrillic 'ө' and the Latin 'ƙ', to create domain names that appear visually identical to legitimate URLs in Unicode but are distinct in Punycode. These characters are not on the hardcoded lists used by browsers to detect spoofing attempts. The current browser defenses, which include a seven-step check for common spoofing methods and a comparison against a list of popular websites, fail to catch these new lookalike domains. Consequently, attackers can register domains that impersonate popular websites, potentially leading users to phishing or malicious sites without triggering standard browser warnings or displaying the Punycode equivalent.
The effectiveness of current browser security measures against homograph attacks is significantly diminished by the introduction of new Unicode characters that exploit existing detection logic. Chromium's defense relies on specific character lists and comparison algorithms that are proving inadequate against these novel spoofing techniques. This vulnerability highlights an ongoing cat-and-mouse game between security researchers and malicious actors, where new character sets continually challenge the efficacy of established browser protections.
This development poses a substantial risk to users and organizations reliant on secure web browsing, as it expands the attack surface for phishing and credential theft. The ability to register domain names that bypass standard safety checks necessitates a re-evaluation of how browsers handle internationalized domain names and prompts for enhanced, perhaps AI-driven, anomaly detection. Users must remain vigilant, as even sophisticated browser defenses can be circumvented by clever use of character encoding.
AI-written summary. May contain errors.