Two characters open up a world of typosquatting opportunities in Chromium browsers

Summary

Attackers are exploiting rare Cyrillic and Latin characters that look identical to standard Latin letters in Chromium browsers. This allows them to create typosquatted domains that are difficult for users to distinguish from legitimate websites.

IFF Assessment

FOE

This vulnerability allows attackers to impersonate legitimate websites, increasing the risk of phishing and credential theft for users.

Defender Context

Defenders need to be aware of this sophisticated typosquatting technique that leverages homograph-like characters within Chromium. Organizations should educate users about the potential for visually identical but malicious URLs and consider implementing domain monitoring and filtering strategies that can detect these character variations.

Read Full Story →