{"id":61509,"date":"2026-10-10T10:15:00","date_gmt":"2026-10-10T10:15:00","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5302383"},"modified":"2026-10-10T10:15:00","modified_gmt":"2026-10-10T10:15:00","slug":"two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/","title":{"rendered":"Two characters open up a world of typosquatting opportunities in Chromium browsers"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/262149.jpg?imageId=262149&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<p><!-- placeholder(#1) --> <\/p>\n<p>Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses.<\/p>\n<p>Wangling a domain name to look an awful lot like that of a popular website is nothing new. We\u2019ve all encountered phishing sites such as macrosoft[.]com and applle[.]com before in our daily struggles against spam.<\/p>\n<p>However, as browsers mature, new characters are always being made available for use. This opens up new opportunities for those whose languages contain characters\/homoglyphs that aren\u2019t ASCII-compliant, but it also introduces new ways for attackers to abuse display logic quirks in programs like Chrome and Edge.<\/p>\n<p>According to Ian Muscat and Leanne Briffa of <a href=\"https:\/\/haveibeensquatted.com\/blog\/turning-idn-edge-cases-into-typosquats\" target=\"_blank\" rel=\"nofollow\">Have I Been Squatted,<\/a> there are still characters available to cyber-imposters that can reliably fool web users into trusting URLs that they certainly should not.<\/p>\n<p>The latest glyphs bypassing browser safety checks allow tricksters to run websites from a clearly fake domain name (when displayed in Punycode), although they appear just like the real deal in Unicode.<\/p>\n<p>The characters of note, in this case, are \u04e9, which is found in various Cyrillic languages such as Kazakh, Mongolian, and Tatar, and the Latin K with hook, \u0199, used in Hausa and Karai-karai.<\/p>\n<p>Both are visually similar to the letters e\/o, i, and k, respectively, and allowed the researchers to register 20 lookalike domain names.<\/p>\n<p>These included:&nbsp;<\/p>\n<ul>\n<li>\n<p>a\u0440\u0440\u04cf\u04e9[.]com<\/p>\n<\/li>\n<li>\n<p>s\u0440\u0430\u0441\u04e9\u0445[.]com<\/p>\n<\/li>\n<li>\n<p>o\u0199ta[.]com<\/p>\n<\/li>\n<li>\n<p>ni\u0199e[.]com<\/p>\n<\/li>\n<\/ul>\n<p>Below are the URLs\u2019 Punycode equivalents \u2013 how browsers should display them safely:<\/p>\n<ul>\n<li>\n<p>xn--80a6aa68c8d.com<\/p>\n<\/li>\n<li>\n<p>xn--80a5aeq0fr0c.com<\/p>\n<\/li>\n<li>\n<p>xn--ota-f6a.com<\/p>\n<\/li>\n<li>\n<p>xn--nie-g6a.com<\/p>\n<\/li>\n<\/ul>\n<p>You can try them out; they\u2019re registered by Have I Been Squatted and are safe to visit.&nbsp;<\/p>\n<p>They take you to research demo pages set up by the researchers, and each page explains how exactly they bypass browser protections.<\/p>\n<p>Crucially, they all bypass the key security measures deployed by Chromium-based browsers.<\/p>\n<h3>How the bypasses work<\/h3>\n<p>Browsers deploy two main defense layers. The first is a set of seven sequential checks run by Chromium\u2019s SafeToDisplayAsUnicode function, which check for a range of common spoofing methods.&nbsp;<\/p>\n<p>Vendors began introducing these checks in 2017 after researcher Xudong Zheng registered \u0430\u0440\u0440\u04cf\u0435.com \u2013 a domain consisting of all-Cyrillic characters.<\/p>\n<p>Chromium\u2019s checks, which factor in a hardcoded list of known Cyrillic characters known to be used in place of Latin letters, can be seen as &#8220;all or nothing.&#8221;<\/p>\n<p>Built to detect all-Cyrillic strings, the measure only takes action against domain names if every character in the string is on its hardcoded list.&nbsp;&nbsp;<\/p>\n<p>If one character is missing, the check is bypassed. Characters such as \u04e9, \u0457, and \u04af, are known as \u201cbreakers,\u201d as these are not present in the lookalike list, as of <a href=\"https:\/\/developer.chrome.com\/release-notes\/154\" target=\"_blank\" rel=\"nofollow\">Chrome 154<\/a>&nbsp; (released to stable channel on September 22).<\/p>\n<p>Failing any of the seven display checks tells the browser that the characters are unsafe to display as Unicode and to instead display the Punycode, revealing just how dissimilar they are to the genuine domains they try to imitate.<\/p>\n<p>The second measure browsers take is to compare the domain name against a list of popular websites to see if it is trying to imitate one of them.<\/p>\n<p>In Chromium, these checks are handled by the GetSimilarTopDomain() function. This step converts a supplied domain name into a &#8220;skeleton,&#8221; stripping its characters of diacritics, such as accents (\u00f3 becomes o), and checking the skeleton URL against a hardcoded list of popular websites.&nbsp;<\/p>\n<p>Chromium checks against almost 8,500, and if the skeleton matches any of them, then it displays Punycode.<\/p>\n<p>However, the Latin K with hook, \u0199, does not have an accent, and is added to the skeleton as a Latin k with an added combining mark, bypassing the security check.<\/p>\n<p>In this case, the skeleton is formed as: [o k \u2018 t a . c o r n].<\/p>\n<p>(The skeleton maps &#8220;m&#8221; to &#8220;rn&#8221;).<\/p>\n<p>Likewise, with \u0430\u0440\u0440\u04cf\u04e9.com, the Cyrillic barred o retains its bar in the skeleton as a combining mark, meaning it does not match the genuine Apple domain.<\/p>\n<p>Its skeleton is formed as: [a p p l o &#8211; . c o r n].<\/p>\n<p>Browsers are always working to stymie these tools of imposterment. Chrome 148 put an end to attackers being able to use \u048f and \u04ff as breakers to imitate their Latin lookalikes, for example.&nbsp;<\/p>\n<p>The two main security checks are not the only lines of defense. Chromium also deploys warnings at the time of navigation called Safety Tips.&nbsp;<\/p>\n<p>An example domain that would bypass the two main checks is \u00ednstagarm[.]com. The inflection on the beginning character is removed and what\u2019s left is essentially the real Instagram domain with two letters swapped.<\/p>\n<p>The Instagarm domain does not match any of the hardcoded sites, nor does it contain any banned characters.<\/p>\n<p>In this case, <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/09\/chromes-zero-day-whac-a-mole-continues-with-fifth-exploited-bug-of-the-year\/5252689\" target=\"_blank\">Chrome<\/a> will display one of two popups, asking the user if they meant to visit the genuine domain, warning that the current direction of travel appears fake.<\/p>\n<p>However, there are limits to this extra security layer.&nbsp;<\/p>\n<p>The warnings only trigger when an imitation domain is an exact-character match, a one-edit match, or a match with an adjacent swap from the genuine URL. Two or more changes, like with \u0430\u0440\u0440\u04cf\u04e9[.]com, which has all-Cyrillic characters preceding the &#8220;.com,&#8221; will not trigger these warnings.<\/p>\n<p>The warnings will also not trigger with domains consisting of fewer than five characters. Domains such as o\u0199ta.com, which is only one edit from the real Okta, may not trigger defenses because of the one-edit rule and the fact that it is only four characters.<\/p>\n<p>Safety Tips also checks the skeleton against the sites users visit regularly, not just the hardcoded list of trusted sites. Frequently visited sites may trigger the same warnings, but for users who do not have a comprehensive visit history, the defense layer may fail.<\/p>\n<p>The defenses described here only apply to browsers.&nbsp;Email clients are even less picky with imitation domain strings. <\/p>\n<p>Websites like <a href=\"https:\/\/www.theregister.com\/software\/2026\/03\/31\/gmail-adds-ability-to-change-usernames-after-22-years\/5220085\" target=\"_blank\">Gmail<\/a> displayed each of the 20 domains HIBS fed the clients, which were a mix of lookalikes and genuine internationalized domain names (IDNs), as an attacker would want it to, all in Unicode. <a href=\"https:\/\/www.theregister.com\/applications\/2026\/07\/09\/microsoft-to-switch-off-owa-light-after-nearly-two-decades\/5269099\" target=\"_blank\">Outlook Web<\/a> showed all 20 as Punycode, even the harmless ones, suggesting neither apply the right checks to properly inform users.<\/p>\n<p>To quantify the scale of the issue, the researchers looked at ICANN\u2019s list of every .com domain. There are around 167 million of them, approximately 733,000 of which are IDNs, those that contain non-ASCII characters and are stored in Punycode form.<\/p>\n<p>The researchers took each of the IDNs and swapped their non-ASCII characters for ASCII equivalents to determine how many matches there were. They found around 162,000 pairs \u2013 IDNs that resemble plain ASCII domains.<\/p>\n<p>It should be said that this does not mean there are circa 162,000 <a href=\"https:\/\/www.theregister.com\/security\/2024\/11\/05\/typosquat-campaign-impersonates-287-popular-npm-packages\/816810\" target=\"_blank\">typosquatted domains<\/a>, just that many yield lookalikes. Some may be registered by businesses for defensive purposes; others may be owned by the same business that wants to operate multiple websites catering to different languages.<\/p>\n<p>However, organizations should be aware of the means available to typosquatters, and monitor registered domains accordingly. \u00ae<\/p>\n<p> <img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=262149&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/10\/10\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/5302383\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Attackers abusing rare Cyrillic and Latin letters to impersonate popular websites READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":61510,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61509","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Two characters open up a world of typosquatting opportunities in Chromium browsers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Two characters open up a world of typosquatting opportunities in Chromium browsers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-10T10:15:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/262149.jpg?imageId=262149&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Two characters open up a world of typosquatting opportunities in Chromium browsers\",\"datePublished\":\"2026-10-10T10:15:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/\"},\"wordCount\":1211,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/\",\"name\":\"Two characters open up a world of typosquatting opportunities in Chromium browsers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg\",\"datePublished\":\"2026-10-10T10:15:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg\",\"width\":100,\"height\":66},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Two characters open up a world of typosquatting opportunities in Chromium browsers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Two characters open up a world of typosquatting opportunities in Chromium browsers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/","og_locale":"en_US","og_type":"article","og_title":"Two characters open up a world of typosquatting opportunities in Chromium browsers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-10-10T10:15:00+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/262149.jpg?imageId=262149&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Two characters open up a world of typosquatting opportunities in Chromium browsers","datePublished":"2026-10-10T10:15:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/"},"wordCount":1211,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/10\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/","url":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/","name":"Two characters open up a world of typosquatting opportunities in Chromium browsers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/10\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg","datePublished":"2026-10-10T10:15:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/10\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/10\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers.jpg","width":100,"height":66},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"Two characters open up a world of typosquatting opportunities in Chromium browsers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61509"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61509\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/61510"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}