Researchers Found Security Bypass in Chromium Browsers
Two specific characters enable attackers to create lookalike URLs that evade browser security checks.
Updated on Oct. 10, 2026 in Cybersecurity

Live Poll
Do you trust that the web addresses displayed in your browser are always the genuine sites?
Researchers have identified that the characters ө and ƙ can bypass Chromium browser security, allowing lookalike domain names to display as Unicode. These characters exploit gaps in existing spoofing protection functions, potentially tricking users.
Why it matters
The vulnerability demonstrates how attackers can circumvent protections designed to stop typosquatting. Because these characters are not on hardcoded lists, browsers may fail to identify deceptive URLs as malicious.
Chromium utilizes seven sequential display checks and a GetSimilarTopDomain function against 8,500 popular websites to prevent spoofing. Researchers confirmed this security bypass by registering 20 test domains.
The players
Chromium
This is an open-source browser project that serves as the foundation for Google Chrome and various other web browsers.
The details
The Chromium SafeToDisplayAsUnicode function misses characters like ө because they are not on the hardcoded list of lookalikes. Additionally, the ƙ character is processed as a Latin k with a combining mark, bypassing skeleton matching checks that compare domains against lists of popular sites.
Timeline
In 2017, vendors began introducing seven sequential display checks.
Chrome 154 was released to the stable channel on September 22, 2026.
The research regarding these typosquatting vulnerabilities was published on October 10, 2026.
The Tech Race
This vulnerability highlights the ongoing challenge of maintaining browser security in an era of Internationalized Domain Names. It follows the evolution of the Chromium SafeToDisplayAsUnicode function, which has sought to protect users from typosquatting since 2017.
Users may be at an increased risk of visiting malicious websites that appear legitimate due to these lookalike URL displays. Until browser developers update security filters, individuals should exercise caution by verifying the actual domain name before entering sensitive data.
The takeaway
Users should remain vigilant against suspicious links even when browsing on popular platforms like Gmail or Outlook Web. Always inspect the browser address bar carefully for irregularities that might signal a lookalike domain attempt.
Further reading
Learn more about evolving digital threats in our Cybersecurity section.
Source note: This article includes information reported by TheRegister.
Live Poll
Do you trust that the web addresses displayed in your browser are always the genuine sites?







