Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Three Cyrillic letters still let lookalike domains through Chromium's address-bar check

Researchers at haveibeensquatted.com found three Cyrillic letters that still break Chromium's whole-script lookalike check in current Chrome. A name built on one can display close to a real brand, so the address bar is a weaker check than users are taught.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Three Cyrillic letters still let lookalike domains through Chromium's address-bar check
Generated illustration

What happened

  • Under ICU 78, 64 lowercase Cyrillic characters are both allowed by Chromium and absent from its 29-character Cyrillic lookalike list.
  • Chrome 148, released in May 2026, adopted ICU 78.2 and Unicode 17, and the Unicode reclassification now blocks two of the five breakers the researchers named.
  • The work revisits Xudong Zheng's April 2017 Cyrillic .com, drawn by Chrome, Firefox and Opera as near-identical to a real domain and shown by Chromium as Punycode ever since.

Why it matters

  • exposure Machines still on Chrome 147 or earlier accept all five breaker characters, so slow browser updates widen the set of lookalikes that render as Unicode.
  • constraint Mail clients draw sender addresses by their own rules, so a change to Chromium's lookalike list would not cover a deceptive address in an email From line.
  • precedent Chrome 148 closed two breakers only because Unicode 17 reclassified them, so the remaining three stay usable until Chromium edits its 29-character list or Unicode reclassifies them as well.

The weak point is in stage 1, in the whole-script confusable rule. Chromium runs the first part of its check through International Components for Unicode (ICU) with a narrowed set of allowed characters, then adds rules of its own [11]. The confusable rule is all-or-nothing. A single Cyrillic character missing from the lookalike list takes the whole label outside the rule [12]. The researchers call that character a breaker [12]. To be useful it must sit in Chromium's allowed set, stay off the lookalike list, and still pass for a Latin letter to someone reading the address bar [13].

Many characters clear the two software tests. Few look enough like a Latin letter to fool a reader. The researchers name five that do [15], about one in thirteen of the candidates [22]. One is a letter used in Kazakh, Mongolian and Tatar that Chromium does not list as a lookalike [19].

A breaker gets a label through stage 1 and no further [9]. Every letter in the label must also be Cyrillic. Several Latin letters have no Cyrillic substitute in Chromium's allowed set, and Chrome 148 removed the substitutes for two more [17]. That limits which brand names can be spelled at all. Stage 2 then reduces the full hostname to comparison strings, called skeletons, and checks them against a bundled list of popular domains. If the hostname matches a different site, the whole name goes back to Punycode [18]. The registry also decides which characters a name may contain [20]. We'd rate the technique exploitable today, but only against brand names that can be written entirely in permitted Cyrillic. The researchers say they found two edge cases that still let a convincing lookalike through [8]. They credit the breaker technique for the name Chrome 154 displays in their opening screenshot [6].

The address-bar advice dates from when domain names could only hold English letters, digits and a hyphen [1]. Names have been able to use almost any writing system since 2003 [2]. For those names the advice depends on Chromium showing deceptive-looking labels in Punycode instead [3]. In our view, reading the address bar still helps, but it has to sit alongside controls that do not rely on a person reading the name correctly. The published findings do not report any attacker using the technique, and they do not describe a Chromium change for the three characters that still pass.

What to watch

  • Whether Chromium adds the three remaining breaker characters to its Cyrillic lookalike list, or a later ICU or Unicode release reclassifies them.
  • Registrations of all-Cyrillic labels using these characters that spell popular brand names, the first sign of the technique moving from research into phishing.
  • Fuller detail on the researchers' second edge case, and whether it reaches stage 2 for brand names the first one cannot spell.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The 'check the address bar' advice assumes the name there can be read correctly, which held while domain names could only contain English letters, digits, and a hyphen.

    ReportedSupportedView cited source
  2. [2]

    Since 2003 domain names can use almost any writing system.

    ReportedSupportedView cited source
  3. [3]

    Chromium, the engine behind Chrome, Edge and other browsers, applies a display check: if a name looks built to deceive, the address bar shows its encoded Punycode form instead.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. haveibeensquatted.com

    1 article · October 9, 2026

    https://haveibeensquatted.com/blog/

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories