P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Two characters put 20 lookalike domains past Chromium's checks: a 29-letter list and an 8,462-domain list

Researchers at Have I Been Squatted registered 20 lookalike domains with two characters that Chromium's display checks let through, because the checks are a list of 29 Cyrillic letters and a list of 8,462 domains. No use in the wild, no fix and no Google statement is reported.

By Parminder Kumar Sharma · · 31 min read

A dark room with two near-identical brass nameplates side by side on a walnut desk at the right of the picture. Each has four screws and an empty recessed panel. The right plate is slightly darker and redder, with a small dimple at each end of its panel. The left is empty dark, with the headline and a stat drawn over it: 29 letters.

Two characters, 20 domains, and a defence that is two lists

Have I Been Squatted registered 20 lookalike domains, all in .com, using two characters. The Cyrillic letter U+04E9 (CYRILLIC SMALL LETTER BARRED O, which looks like a Latin o or e) is in 15 of them, and the Latin letter U+0199 (LATIN SMALL LETTER K WITH HOOK, which looks like a Latin k) is in the other 5 (counts derived from the 20 names the researchers list). Their write-up of 3 October 2026 shows Chrome 154 displaying one of the Cyrillic names in Unicode, with a valid certificate, as if it were a famous brand's genuine address. It works because Chromium's two lookalike defences are lists. One is a list of 29 Cyrillic letters, and it blocks a Cyrillic label only if every letter in the label is on it. The other is a list of 8,462 popular domains, and a lookalike has to match one of them. A letter that is not on the first list, or a brand that is not on the second, is not tested. Both counts were made by this briefing from Chromium's source files as read on 10 October 2026.

"Two characters" is the size of the demonstration, not the size of the gap. The researchers' own table names three Cyrillic letters that pass today (U+04AF, U+04E9 and U+0457), and says that 64 lowercase Cyrillic letters in Chromium's allowed set are not on the 29-letter list. This briefing reproduced the 64 from the Unicode 17.0.0 data files and the list in the source (derived). It does not follow that 64 letters are usable: the researchers' third test, that the letter looks like a Latin one to a reader, is a judgement, and they name five letters that met it.

What that does not establish matters as much as the count. No source read reports any use of these characters in an attack, and none says there has been none. No statement from Google or Microsoft was found, and no fix for these characters: in the source as read on 10 October, and unchanged on a re-read at 20:30 BST, the three Cyrillic letters are still off the list. Nothing read says whether Firefox or Safari show these labels as Unicode, because the researchers did not test them. The researchers did not measure Safe Browsing, spam filtering or link scanning against the 20 domains. No victim count exists. And the write-up is a vendor's: Have I Been Squatted sells lookalike-domain detection and takedown, and its post ends with an offer of a free trial. Its figures are checkable, and the ones used here were checked.

What the count does show is where the control sits. A list of known-bad letters fails open: it allows whatever it has not been told to block. A list of popular brands protects the brands on it and no others. Every UK bank, retailer, council and public service that is not on the 8,462 gets no help from the list at that stage. This briefing read the list, so it can say what is on it: 71 entries end in .uk, four of them in .gov.uk and two in .nhs.uk, and none ends in .ac.uk or .org.uk (counted). The control that does not depend on anyone's eyes is a password manager or passkey that checks the exact origin, and the last section turns that into an ordered list.

The five gates: where each character gets through

The researchers split Chromium's per-label function, SafeToDisplayAsUnicode, into seven checks, and the Register repeats "seven". Chromium's own document lists thirteen steps for the whole decision, and the types file in the source defines ten result codes, eight of them reasons to show Punycode (counted by this briefing). The number depends on where the cut is made. The diagram below uses five gates, the ones that matter for these two characters, and each statement in it was checked against the source or a published table.

A vertical chain of five gates with two lanes. Left lane: a Cyrillic barred o in a five-letter label. Right lane: a Latin k with a hook in a four-letter brand label. Both pass the registry tables, the allowed-set checks, the skeleton check and the navigation warning. At the whole-script rule the Cyrillic letter is not on a list of 29 so the rule stands down, and Latin has no list. Result: Unicode shown with no warning. A last box says a password manager or passkey checks the exact origin.
Drawn from the researchers' write-up of 3 October 2026, Chromium's source files read on 10 October 2026 and Verisign's published .com tables. The gate wording is this briefing's reading.

Gate by gate, with what the source says:

  • The registry. Verisign's published .com tables list U+04E9 in the Cyrillic table (version 1.2, effective 25 October 2014) and U+0199 in the Latin table (version 2.6, effective 4 March 2020). Both tables are as listed by IANA on 10 October 2026.
  • Allowed set and script mixing. The label has to use allowed characters and one script, and some letters are accepted only under some top-level domains. A label written entirely in Cyrillic, or entirely in Latin, with allowed letters, passes.
  • The whole-script rule. For 17 scripts the source holds a list of letters that look like Latin ones. If every letter of a single-script label belongs to the list, the label is shown as Punycode, unless the top-level domain suits the script (for Cyrillic: bg, by, kz, pyc, ru, su, ua and uz, or any TLD containing a Cyrillic letter) or the label is one of 12 allowed words. The check uses a set-containment test, so one letter off the list ends it. A comment in the source says ICU's own whole-script check has been a no-op for a single string since ICU 58.1, and Chromium's check is its own list.
  • The skeleton check. Chromium removes accents, applies its own extra mapping and then ICU's UTS #39 mapping, and compares the result with the list. A letter such as U+0199 has no accent to remove, so it is not stripped. Unicode's confusables file then maps it to a k plus a combining mark, and U+04E9 to an o plus a combining bar. Neither letter appears in Chromium's extra mapping (searched), so the mark stays and the skeleton no longer equals the brand's.
  • The navigation warning. A later check compares the skeleton with sites the user visits often and with the top group of the list, and looks for one edit or one swap. It skips names with fewer than five characters before the suffix, on either side of the comparison: the source builds its near-match list only from names that pass that test, and applies it to the visited name as well. In the researchers' examples a Cyrillic lookalike of a five-letter brand is two edits away, and the four-letter brand is below the threshold.

The five-character threshold is in the code as a constant, with a comment that gives a UK example: a name such as abc.co.uk has a length of 3 and "will not be considered". Near matches, one edit or one swap, are looked for only against the top group of the list and against sites the visitor uses often, and an exact skeleton match is looked for against all 8,462. Of the 836 names in the top group, 138 have fewer than five characters before the registry suffix, leaving 698 as near-match targets, and across all 8,462 the figure is 1,034, or 12.2 per cent (counted using the Public Suffix List; the researchers give the rule, not these counts). Twelve of the 71 UK entries have fewer than five characters, and three of the nine UK names in the top group do.

The two lists, as read in Chromium's source

The 29 letters. The Cyrillic list in the source holds 29 letters (counted). Until a commit dated 11 September 2026 it held 28. That commit adds U+043C, and its message says the letter "was omitted" and let Cyrillic labels containing it "bypass whole-script-confusable detection". It adds: "This change does not impact a significant number of sites' URL displays in Chrome." The researchers say Chrome 155 still ships 28 letters. The issue behind the commit is marked access-denied on the tracker, so who reported it and when is not stated. The point for this briefing is the pattern: the defence is extended one letter at a time, and the letters it has not been extended to are the gap. The researchers record the same pattern in Chrome 148, released on 5 May 2026, which they say moved to ICU 78.2 and so stopped accepting two letters (U+048F and U+04FF). Unicode's 17.0.0 identifier-type file marks both as Uncommon_Use (read).

The 8,462 domains. The file holds 8,462 names, one per line, with a marker after the first 836. The header says it was generated from the Chrome User Experience Report table for September 2023, 37 months before the read (derived from the table name; the date of the file's last change could not be read because GitHub's history request failed). The fetch script in the same folder keeps hostnames with a popularity rank of 10,000 or better, treats rank 1,000 or better as the top group, adds three hosts by hand, and removes duplicates. That is a global popularity list. It has 3,777 names ending in .com (44.6 per cent), 392 in .net and 188 in .org (counted). Chromium's own documentation says the code restricts "domains that are similar to top 10k domains" in a document last updated on 25 June 2019, and its interstitial steps say "top 500 domain" while the file's top group has 836 entries. That mismatch is Chromium's, and this briefing does not resolve it.

UK names on the 8,462-entry list, counted by this briefing from the file in Chromium's main branch on 10 October 2026. Suffix counts are of entries ending in the suffix. Names are those in the file.

What was countedCountWhat it means
Entries ending in .uk71 of 8,462 (0.84 per cent)65 end in .co.uk, 4 in .gov.uk and 2 in .nhs.uk. The 4 are the Met Office, GOV.UK's service domain, Transport for London and www.gov.uk; the 2 are the NHS site and its jobs site.
Entries ending in .ac.uk, .org.uk, .police.uk or .sch.uk0None of these suffixes appears, so universities, police forces and schools that use them are not covered. Councils are not on the list either: the only .gov.uk names are the four above.
Bank and building-society names among the 714barclays.co.uk, halifax-online.co.uk, lloydsbank.co.uk and nationwide.co.uk. Whether another is on the list under another suffix was not searched.
Of the 71, names under five characters before the suffix12These cannot be near-match targets, and near matches are built from the top group only in any case. An exact skeleton match still applies to all 71.
Entries in the top group (first 836)9 UK names, 3 of them under five charactersAmazon, Argos, the BBC, the Daily Mail, eBay, Google, Rightmove, service.gov.uk and www.gov.uk, all under .uk suffixes. The three under five characters are the BBC, eBay and www.gov.uk, by the code's rule.

What a brand outside the list gets. The skeleton check at the second stage compares a name with this file only. A lookalike of a brand that is not on it is not turned into Punycode by that stage, and the near-match warning has no target for it. The navigation warning adds one more source, the sites an individual visitor uses often: for a visitor who uses the real site a lot, the write-up says an exact skeleton match shows a full-page warning, and a near match shows a Safety Tip. Chromium's own page says warnings are shown only on sites the user has not used frequently, and that only well-known sites or sites with an established relationship are recommended. A customer who is new to the brand, or a member of staff who does not use the real site, has neither. By this briefing's reading of the lookup code, the skeleton is compared in full, suffix included, so a lookalike of a name on the list under .co.uk would have to be under the same suffix to match. That is inference from reading the code, not a test, and a brand owner should not rely on it.

How a brand owner can check. The file is public in Chromium's source tree: search it for your registrable name, exactly as you write it, and for each suffix you use. If it is absent, assume the skeleton check does not cover you. How to ask for inclusion: no route was found. The folder's README says updates follow an internal process, and the fetch script takes the popularity ranking, so inclusion follows traffic and not a request. Chromium's lookalike page describes review requests for sites that are wrongly flagged, which is the opposite request.

The multiplication. Each extra letter that a browser accepts and that resembles a Latin one enlarges the set of brandable lookalikes, because the number of spellings of a name is the product, across its letters, of the number of look-alikes available for each. As an illustration only, with no domain in mind: a five-letter label in which every letter has two acceptable look-alikes has 2 x 2 x 2 x 2 x 2 = 32 spellings, and giving one letter a third raises it to 48. The researchers add the Latin side: a Cyrillic lookalike has to replace every letter, while a Latin one can change a single letter. In Unicode's confusables data (version 18.0.0, dated 6 August 2026) this briefing counted 1,656 non-ASCII characters whose prototype is made only of basic Latin letters, 1,447 of them single letters, and 234 whose prototype is a Latin letter followed by a combining mark, which is the class the two characters belong to. These are counts of what the data contains. They include symbols and scripts that browsers and registries exclude, and they are an upper bound, not a count of usable characters.

What is stated, by whom, and what is not

The Register's article of 10 October 2026 is a second reading of the researchers' write-up of 3 October, a week earlier, and adds no testing of its own and no statement from Google or Microsoft. This briefing treats the write-up as the primary source for the findings and read the Chromium files, Unicode's data and the registry tables as primaries for what the write-up claims about them. Four points where the article and the primaries read differently matter:

  • Seven checks. The article repeats the researchers' count of seven. Chromium's documentation lists thirteen steps for the whole decision, and the source defines ten result codes.
  • "Almost 8,500". The file holds 8,462 names, 836 of them in the top group.
  • "Two characters". The write-up's table lists three Cyrillic letters that pass today and two that passed until Chrome 148, and the hooked-letter route is a class: the write-up says a hook or a stroke behaves the same way.
  • The mail test. The article says Gmail displayed each of the 20 domains the researchers fed the clients and Outlook Web showed all 20 as Punycode. The write-up says the test used 20 internationalised senders, a mix of lookalikes, accented spellings of top names and ordinary IDNs, not the 20 registered names, with two ASCII controls. It also says Gmail's mailed-by field shows the encoded form, which is not the address a reader checks.

Claims about the research, with the source that makes each, read on 10 October 2026. Counts and day counts are derived from the sources and their dates.

QuestionStated, and by whomNot stated
Were these characters used in attacks?Neither the Register nor the write-up reports use. The researchers registered the 20 domains themselves, and say each lookalike pair they counted in .com is a potential imitation, not a confirmed typosquat.Any use in the wild. Equally not stated: that there has been none.
Is it fixed?Chrome 148 (5 May 2026) rejects two other letters (the write-up). Chromium added a 29th letter on 11 September 2026 (the commit). In the main-branch source as read on 10 October, and unchanged on a re-read at 20:30 BST, U+04E9, U+04AF and U+0457 are still off the list (read).Any Google statement, tracker entry or fix for these characters or for hooked and stroked Latin letters. Four Chrome stable posts from 22 September to 6 October list Omnibox items but none names IDN, lookalike or homograph. The issue behind the 11 September commit is access-denied.
Does Edge share it?The write-up says Chromium is the engine behind Chrome and Edge. Edge's security notes list Edge 155.0.4283.45 on 8 October 2026, and Edge 154 builds from 24 September.Any Microsoft statement, any test of Edge, and whether Edge adds checks of its own. The notes read mention no IDN or lookalike change.
Do Firefox and Safari show these labels as Unicode?The write-up examines Chromium most closely. Firefox's source (read) has its own hard-coded Cyrillic list of 28 letters without the three. WebKit's source (read) says Apple platforms load the script allow-list from a file.Any test of either browser, and Apple's default script list. The compiled default in WebKit's shared code leaves Cyrillic out, but the Apple implementation is not in the source read.
Do other defences catch them?The researchers did not measure spam filtering, sender reputation or link scanning. Chromium's documentation names Google Safe Browsing and password managers as other layers.Whether Safe Browsing, Defender SmartScreen or a mail gateway blocks any of the 20.
Did the registry allow them?Yes, by its published tables: U+04E9, U+04AF and U+0457 are in Verisign's Cyrillic table and U+0199 in its Latin table. The main demonstration name was registered on 26 September 2026 (registry record) and the write-up appeared 7 days later (derived).Any other registry or registrar rule that screened them. Nominet's position on IDNs in .uk was not read: nominet.uk refused a plain request and was not pursued.
How many people are affected?No count of people. The write-up counts names in the .com zone: 733,509 IDNs among 167,226,216 delegated names (0.44 per cent, derived), and 161,894 lookalike pairs.Users, victims, or how many pairs are used for fraud. The write-up says some are defensive registrations or unrelated businesses.

Whose code, whose interest

Each party below has an interest, and the table states it in one sentence without treating it as a verdict on the facts.

What each party published or did, as read on 10 October 2026, and its interest in one sentence.

PartyWhat it published or did, as readIts interest
Have I Been Squatted (the researchers)Registered 20 demonstration domains, published a write-up on 3 October 2026 that carries a 33-minute reading time, ran the Chromium logic offline, and recommends registering variants, monitoring and passkeys.It sells detection and takedown of lookalike domains, so a finding that makes lookalikes look common suits it.
Google (Chromium)Documents a policy of 13 steps, says its lookalike checks aim "not to make spoofing impossible, but to force attackers to use less convincing lookalikes", and says IDN display is "a limitation of how URLs are displayed in browsers in general, not a specific bug in Chrome".It must show non-Latin names to billions of people, and its own page says showing Punycode too widely would hurt usability.
Microsoft (Edge, Outlook Web)Ships Edge on Chromium and Outlook Web, which printed all 20 test senders in encoded form in the researchers' test, including ordinary names such as a Swiss city. Its Edge notes for 154 and 155 do not mention the research.It ships both a browser that inherits Chromium's lists and a mail client that avoids the problem by decoding nothing.
Mozilla (Firefox)A wiki page last edited on 17 April 2017 says its system permits whole-script confusables and that "it is up to registries" to stop customers ripping each other off. Its source holds a 28-letter Cyrillic list.It wants non-Latin scripts treated as equals, and prefers that registries do the policing.
Apple (Safari, WebKit)No IDN display policy page was found. WebKit's source says Cocoa loads the allowed scripts from a file. A Safari Technology Preview 238 note dated 26 February 2026 fixes an IDN homograph displayed as a Latin domain.It sets Safari's default and publishes the least of these vendors about it, so its position cannot be read from its pages.

Two further parties matter and are not in the table because they do not ship a browser. Verisign operates .com and publishes the tables that allowed these registrations, so its interest is in the registry it runs. The Unicode Consortium publishes the data the checks draw on, and its standard describes itself as an independent specification, so each implementer decides how to use it. Its text says confusability "cannot be an exact science", that the data "may be refined and extended over time", and that a skeleton is for internal testing only. It also warns that a whole-script test is "likely to flag a large number of legitimate strings" in Latin or Cyrillic, which is why Chromium's list is short and why it keeps 12 allowed Cyrillic words: a longer list would block honest names. ICANN's IDN guidelines (version 4.1, 22 September 2022) say all code points in a label should come from one script, with exceptions, but only "encouraged" registries to minimise whole-script confusables, so the registry layer is advisory. The design is a trade between false alarms and misses, and these two characters sit on the miss side.

A typosquat is a typing mistake. This is a display decision

"Typosquatting" names a technique in which a visitor mistypes or misreads a name. The Register's headline uses it, and so do the researchers. For these 20 names the label points to the wrong party. Nobody mistyped anything, and nobody misread: the browser chose to show the Unicode form, and the address bar then displayed, to the eye, the same name as the genuine one. The failure is in a decision the user cannot see being made. The researchers open with the advice this undermines: "Check the address bar" is the one piece of security advice everybody has heard. It assumes the name there can be read correctly, which was true while names could only use English letters, digits and a hyphen.

The history gives a sense of scale. The write-up says the whole-script check arrived in Chrome 58, and the Chrome Releases post promoting 58 to stable is dated 19 April 2017 and lists CVE-2017-5060, URL spoofing in the Omnibox, for the bug Chromium's own document cites as the all-Cyrillic report. From that date to the Register's article is 3,461 days, about 9.5 years (derived). The response the sources describe, in the Chrome 148 change and in the 11 September 2026 commit, is to adjust a list when a letter is found. Chromium's own page states the aim: "not to make spoofing impossible, but to force attackers to use less convincing lookalikes". It adds that Chrome cannot detect all lookalike domains. By that stated aim, a lookalike that reads the same as the genuine name is a miss, and the 20 are misses. The page does not promise otherwise, and that is the case against relying on the address bar.

The researchers' demonstration page is a single page that shows the genuine name and its lookalike side by side in the viewer's own font, a timeline of 15 earlier lookalike incidents from 2006 to 2026, and five habits: do not trust how an address looks, go to sites directly, let a password manager fill logins, use passkeys or security keys, and keep the browser up to date. It states that it is not affiliated with the brand it imitates and asks for no information. This briefing read its text and verified none of the incident descriptions on it.

The pattern has come up in earlier briefings: a label or an address is shown as the control, and it is not. A documentation placeholder nobody reserved served a lure where the request was the detection. A Google ad showed bing.com while four stops carried the click elsewhere. A browser-in-the-browser page drew its own address bar. In each, the thing a person reads was the part the attacker controlled.

Why the registry and the certificate authority did not stop it

These names could be registered because U+04E9 is a letter of Kazakh and other languages, and the hooked k is used in Hausa (the Register's wording), and the registry's tables are written to let each language's letters through. The tables are per script, a label is checked against the table for its declared script, and a label that mixes Latin and Cyrillic therefore usually fails at registration (the write-up's account; Verisign's page says registrations are checked against language tables and a policy of permissible and prohibited code points). The Latin table, version 2.6, lists 587 non-ASCII code points (the write-up's figure, confirmed from the file), and no variant rules appear in the file. The Cyrillic table is 12.0 years old (derived from its 25 October 2014 effective date) and is still the current one on the IANA list. The tables do what they say. They keep a label in one script, and they cannot leave out a letter that a language uses.

The main demonstration name was registered on 26 September 2026 by the registry's own record. Public certificate logs show six entries for it, with not-before dates on 26 and 27 September from three public authorities, and the live certificate came from Google Trust Services, valid from 27 September to 26 December (read). One oddity: the earliest logged entry carries a time earlier on 26 September than the registry's registration time, which this briefing cannot explain and does not rely on. The defender point, from one example: a lookalike had public certificate entries within a day or two of registration, so a search of certificate logs is one place a live lookalike appears early. The NCSC advises certificate monitoring for your own domain, and does not say whether it covers confusable names.

UK reading: what each source says, and where it does not reach

The exposed group is any UK organisation whose customers, staff or citizens could be sent to a lookalike of its name: a bank, a retailer, a council, a health body, a government service. The NCSC and Cyber Essentials each describe controls that could apply. The table says what each source says and whether the source claims it stops this. None does. Entries marked inference are this briefing's.

UK controls and what the sources read on 10 October 2026 say about them. NCSC page dates are those shown on each page. Cyber Essentials is v3.3, April 2026, read from the text extraction saved for briefing 283.

Control and sourceWhat the source saysReach for this problem
NCSC Takedown Service (page published and reviewed 20 November 2020)Works with Netcraft and covers UK Government brands and services, focused on "the HMG brand". Central government needs no registration. It scans spam and phishing feeds and takes reports through the Suspicious Email Reporting Service, then notifies hosts and adds sites to safe-browsing lists.A private-sector brand owner is outside its stated eligibility. It acts on live attack pages, not on a registered but unused lookalike (inference).
NCSC takedown and brand impersonation guidance (21 September 2022)Anyone can ask the registrar and the host to act: find the registrar, search for its abuse route, find the IP owner, and keep a screenshot with the full address and time. Requests can take hours, days or weeks. A takedown provider is an alternative, and the NCSC advises planning before an incident.A route for a live abuse. It does nothing about what the address bar shows. The page does not mention IDNs or confusable characters (searched).
NCSC guidance for registrars (27 March 2025)Says it is "extremely common" for abusive registrations to imitate well-known organisations or brands, and that monitoring new registrations can find them before they are used. Names Nominet's Domain Watch.Written for registrars, so a brand owner must do or buy the monitoring (inference). No mention of IDNs (searched).
NCSC guidance for high-risk individuals (29 May 2024), certificate monitoringTo monitor attempts to impersonate your website, use a service that notifies you when a new certificate is issued for your domain.Worded for your own domain. Whether a service also matches confusable names is a product question. The demonstration name has certificate-log entries dated 26 and 27 September 2026.
NCSC Web Check and Mail CheckRetired on 31 March 2026, 193 days before the Register's article (derived). The NCSC recommends commercial external attack surface management products and its Check your cyber security service.Neither was a lookalike monitor in the text read (inference). Anyone relying on them has no findings since 31 March.
NCSC phishing guidance (reviewed 13 February 2024)DMARC, SPF and DKIM stop phishers spoofing your domain. Run a proxy to block sites identified as hosting phishing. Consider password managers, "some of which can recognise real websites and will not autofill on fake websites". No training can teach users to spot every phishing attempt.The page does not use the words lookalike or typosquat (searched). The researchers say SPF, DKIM and DMARC all pass for a lookalike the attacker owns, so email authentication covers your exact domain only.
NCSC passkeys position (23 April 2026) and its FIDO2 paperRecommends passkeys over passwords wherever available. In its comparison table, adversary-in-the-middle phishing is "Never vulnerable" for FIDO2 credentials and "Always vulnerable" for a password with a traditional second factor.The paper is about credentials for personal use, and the NCSC says it has not formally assessed organisations. It needs the service to support passkeys. It does not help a customer who types a card number into a lookalike (inference).
NCSC Protective DNSPrevents access to domains known to be malicious by not resolving them. Free. Mandated for central government and open to other organisations, with eligibility in its FAQ.It acts on domains known to be malicious. A lookalike with no abuse recorded is not on that list (inference).
Cyber Essentials v3.3 (April 2026)The text has no mention of lookalike, typosquat, homoglyph, impersonation, brand or spoof (searched). Its anti-malware option must "prevent connections to malicious websites over the internet". MFA is required for administrative accounts and accounts reachable from the internet, and passkeys and FIDO2 authenticators are "regarded as MFA".It governs your own devices and accounts, so it does not reach a lookalike of your brand aimed at your customers. Its passwordless list also includes push notifications and one-time codes, which the NCSC paper treats as phishable second factors (inference).
Nominet, .ukNot read: nominet.uk answered a plain request with 403 and was not pursued. Nominet's registrar page on IDNs, which was read, covers .cymru and .wales.Whether .uk accepts IDN labels is not stated in anything read, so a UK brand's lookalikes may sit in .com or another suffix.

Two things follow for a UK organisation. For its own staff, a password manager that binds to the exact origin, and passkeys on the consoles that matter, are the controls whose result does not depend on what the address bar shows. Chromium's own page says password managers "won't automatically fill a password into a domain that is not the exactly correct one", and the researchers' demonstration page says the same of passkeys. The earlier briefings on GOV.UK One Login's passkeys and on Report Fraud's passkey campaign cover the limits of that route, and the Chrome 155 release became the stable build on 6 October, three days after the write-up. For its customers, the organisation cannot control the browser, so its levers are to register what is worth registering, to watch what others register, to publish how customers can check it, and to be ready to act when one goes live.

What to do, in the order worth doing

Steps 1 to 3 establish what you must defend and how exposed it is. Steps 4 to 7 reduce the chance and the harm of a lookalike. Steps 8 to 10 prepare the response. All are defender actions, and none needs a lookalike name.

Take this with you

Defender actions, in order

  • Inventory the domains and brand names you must defend: your main names, the names of products and campaigns, and the suffixes you use. Write each as a plain ASCII string.
  • Check each against Chromium's public top-domain list in its source tree, exactly as written and for each suffix. If it is absent, assume the skeleton check does not protect you. No route to ask for inclusion was found, and the list follows popularity.
  • Search certificate transparency logs and new-registration feeds for lookalikes of each name. Include confusable characters in the query, in particular U+04E9, U+04AF and U+0457 in a Cyrillic label and Latin letters with a hook or a stroke such as U+0199. Watch for any new name that begins with the xn-- prefix and is within two edits of a protected name, which is the researchers' advice. Buy the monitoring or build the query, and name an owner.
  • Register the highest-risk variants yourself. The researchers advise registering lookalikes that survive a skeleton comparison, such as those built with the letters above, and registering hooked and stroked spellings directly for any brand of four characters or fewer. A registration is cheap against a campaign that uses it, and it does not need every variant.
  • Move staff to a password manager that binds to the exact origin, and to passkeys for administrative consoles and for the accounts that matter most, so that a lookalike gets no credential. Check each service supports passkeys, and treat the recovery route as part of the control.
  • Turn on impersonation or lookalike protection in your email and web gateways, and tag inbound mail from encoded (xn--) sender domains. In DNS and proxy logs treat encoded names as a signal, and log, banner or block them outside an allowlist: that works on the encoded name, which no display choice can hide (the researchers' advice). Remember that SPF, DKIM and DMARC pass for a lookalike its owner controls, so they do not stop one sending from its own domain.
  • Tell staff to use bookmarks or typed addresses for banking, payroll and administration consoles, and never a link in a message. The NCSC says no training can teach users to spot every phishing attempt, so give them a habit and not a spotting test.
  • Publish how customers can check you: the exact address, an app, and a statement that you never ask for credentials by link. Put it where a customer who doubts a message will look.
  • Rehearse a takedown before you need one: who contacts the registrar and the host, what evidence to keep (a screenshot with the full address and time, and the complete message with headers), who engages a takedown provider, and how a government service uses the NCSC Takedown Service. Record how long each step took.
  • Report this class of display bypass to the browser vendors' security teams, with the characters and the label that shows as Unicode, and keep the report. Chromium's documentation says it rewards certain IDN spoofs under its vulnerability reward rules and points to a document to read first, and that document treats a spoof of the committed address bar as a medium-severity security bug.

What could not be verified

The question that exposes the gap

Every defence in the chain looks at the name: the registry's table, the browser's two lists, the warning, the person reading the bar. The thing that decides whether a login is stolen is none of those. It is whether anything checks the exact origin. So when a customer or a member of staff meets a name that looks like yours, what in your estate answers for the characters nobody put on a list?

Key facts

Sources

  1. PrimaryTurning IDN edge cases into typosquats, 3 October 2026. The researchers' write-up: the 20 demonstration names, the seven-check account of Chromium's display function, the three Cyrillic breakers, the skeleton and navigation checks, the .com zone counts, the webmail test and the recommendations. Read in full, including the collapsed registry section; the demonstration page it links to was fetched as text and its address is not reproducedHave I Been Squattedaccessed 2026-10-10
  2. PrimaryThe display function as source: the ICU checks, the TLD-specific letters, the 17 whole-script lists including the 29-letter Cyrillic list, the set-containment test, the 12 allowed words and the ICU 58.1 comment. Read from the GitHub mirror of the main branch on 10 October 2026Chromiumaccessed 2026-10-10
  3. PrimaryThe skeleton generator: diacritic removal, the extra confusable mapping and the ICU skeleton. Neither U+04E9 nor U+0199 appears in the extra mapping. Read on 10 October 2026Chromiumaccessed 2026-10-10
  4. PrimaryThe ten result codes of the display check, counted. Read on 10 October 2026Chromiumaccessed 2026-10-10
  5. PrimaryThe top-domain list: 8,462 names, a marker after the first 836, and a header naming the September 2023 CrUX table. Counted by this briefing, including the UK suffix counts. Read on 10 October 2026; the date of the file's last change could not be readChromiumaccessed 2026-10-10
  6. PrimaryThe script that builds the list from the Chrome User Experience Report: rank 10,000 or better, rank 1,000 or better as the top group, three hosts added by hand. Read on 10 October 2026Chromiumaccessed 2026-10-10
  7. PrimaryThe five-character minimum for the edit-distance comparison, with a .co.uk example in a code comment. Read on 10 October 2026Chromiumaccessed 2026-10-10
  8. PrimaryThe navigation-time lookalike logic: engaged sites, top-group near matches by one edit or one swap, and the edit-distance candidate test. Read on 10 October 2026Chromiumaccessed 2026-10-10
  9. PrimaryInternationalized Domain Names in Google Chrome: the 13-step display algorithm, the lookalike interstitial steps, defensive registrations and the reporting note. Read on 10 October 2026Chromiumaccessed 2026-10-10
  10. PrimaryLookalike warnings in Google Chrome: the stated aim of the checks, that Chrome cannot detect all lookalike domains, and that warnings depend on browsing history. Read on 10 October 2026Chromiumaccessed 2026-10-10
  11. PrimaryFrequently reported URL spoof bugs in Chromium, last updated 25 June 2019: the near-homoglyph resolution that Chromium restricts domains similar to the top 10k, and the severity given to Omnibox spoofs. Read as text on 10 October 2026Chromiumaccessed 2026-10-10
  12. PrimaryCommit of 11 September 2026 adding U+043C to the Cyrillic whole-script list, with the message that it was omitted. The linked issue is access-denied. Read on 10 October 2026Chromiumaccessed 2026-10-10
  13. PrimaryChrome 154 release notes: stable release date 22 September 2026; no IDN or lookalike item found. Read on 10 October 2026Googleaccessed 2026-10-10
  14. PrimaryChrome 148 release notes: stable release date 5 May 2026. Read on 10 October 2026Googleaccessed 2026-10-10
  15. PrimaryChrome Releases, Stable Channel Update for Desktop, 6 October 2026: Chrome 155.0.8059.39 for Windows and Mac. Read with the 22 September, 29 September and 1 October posts, none of which names an IDN or lookalike fixGoogleaccessed 2026-10-10
  16. PrimaryChrome Releases, 19 April 2017: promotion of Chrome 58 to stable, listing CVE-2017-5060, URL spoofing in Omnibox. Read on 10 October 2026Googleaccessed 2026-10-10
  17. PrimaryRelease notes for Microsoft Edge Security Updates: Edge 155.0.4283.45 on 8 October 2026 and 154 builds from 24 September; no IDN or lookalike mention. Read on 10 October 2026Microsoftaccessed 2026-10-10
  18. PrimaryIDN Display Algorithm, last edited 17 April 2017: the script rules, the statement that the system permits whole-script confusables and that registries are best placed to police them. Read on 10 October 2026Mozillaaccessed 2026-10-10
  19. PrimaryFirefox's IDN service source: a hard-coded Cyrillic lookalike list of 28 letters and the comment that checks whether all the Cyrillic letters in a label are confusables. Read from the tip on 10 October 2026Mozillaaccessed 2026-10-10
  20. PrimaryWebKit's URL helpers: the allowed-script list, the note that Cocoa reads it from a file, and the compiled default that omits Cyrillic. Read on 10 October 2026Apple (WebKit)accessed 2026-10-10
  21. PrimaryRelease Notes for Safari Technology Preview 238, 26 February 2026: a fix for an IDN homograph displayed as a Latin domain. Read on 10 October 2026Apple (WebKit)accessed 2026-10-10
  22. PrimaryUTS #39 Unicode Security Mechanisms, version 18.0.0, revision 34, 27 August 2026: the confusables, skeleton and whole-script text and its statements on limits. Read on 10 October 2026Unicode Consortiumaccessed 2026-10-10
  23. Primaryconfusables.txt, version 18.0.0, 6 August 2026: the mappings of U+0199 and U+04E9 to a letter plus a combining mark, and the counts made by this briefing. Read on 10 October 2026Unicode Consortiumaccessed 2026-10-10
  24. PrimaryIdentifierType.txt, version 17.0.0, with Scripts.txt and UnicodeData.txt from the same release: used to reproduce the researchers' count of 64 and to confirm U+048F and U+04FF are Uncommon_Use. Read on 10 October 2026Unicode Consortiumaccessed 2026-10-10
  25. PrimaryIANA repository of IDN tables: the .com tables published by Verisign, including Cyrillic version 1.2 (2014-10-25) and Latin version 2.6 (2020-03-04). Read on 10 October 2026IANAaccessed 2026-10-10
  26. PrimaryThe .com Cyrillic IDN table, version 1.2, effective 25 October 2014: lists U+04E9, U+04AF and U+0457. Read on 10 October 2026Verisignaccessed 2026-10-10
  27. PrimaryThe .com Latin IDN table, version 2.6, effective 4 March 2020: lists U+0199 and 587 non-ASCII code points. Read on 10 October 2026Verisignaccessed 2026-10-10
  28. PrimaryVerisign's IDN policy page: registrations are checked against language tables, and a policy specifies permissible and prohibited code points. Read on 10 October 2026Verisignaccessed 2026-10-10
  29. PrimaryGuidelines for the Implementation of Internationalized Domain Names, version 4.1, 22 September 2022: guideline 15 on single-script labels and guideline 17, which only encourages constraints on whole-script confusables. Read on 10 October 2026ICANNaccessed 2026-10-10
  30. PrimaryNominet's registrar page on IDNs, covering .cymru and .wales. The .uk policy page on nominet.uk refused a plain request and was not pursued. Read on 10 October 2026Nominetaccessed 2026-10-10
  31. PrimaryThe ICANN-section rules used to count names with fewer than five characters before the registry suffix. Read on 10 October 2026Public Suffix Listaccessed 2026-10-10
  32. PrimaryThe NCSC's Active Cyber Defence Takedown Service, published and reviewed 20 November 2020: Netcraft, UK Government brands, no registration. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  33. PrimaryTakedown: removing malicious content to protect your brand, 21 September 2022: contacting registrars and hosts, evidence, and using a takedown provider. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  34. PrimaryBrand impersonation: the NCSC's steps for an organisation whose brand is being impersonated. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  35. PrimaryGood security practice for domain registrars, page 2, 27 March 2025: imitation registrations and monitoring, naming Nominet's Domain Watch. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  36. PrimaryGuidance for high-risk individuals to protect your website and custom email domain, 29 May 2024: the advice on certificate transparency monitoring. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  37. PrimaryPhishing attacks: defending your organisation, published 5 February 2018 and reviewed 13 February 2024: DMARC, proxies, password managers and the limits of training. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  38. PrimaryNCSC to retire Web Check and Mail Check, 6 November 2025: both retired on 31 March 2026. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  39. PrimaryPasskeys: what you need to know: the NCSC recommends passkeys over passwords wherever available. Read with the 23 April 2026 CYBERUK news item on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  40. PrimaryComparing the security properties of traditional user credentials and FIDO2 credentials for personal use, 23 April 2026: Table 1 and the statement that organisations are not yet formally assessed. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  41. PrimaryProtective Domain Name Service: blocks access to domains known to be malicious by not resolving them. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  42. PrimaryUsing password managers, reviewed and updated 21 May 2026: autofill works only on the correct website. Read on 10 October 2026National Cyber Security Centreaccessed 2026-10-10
  43. PrimaryCyber Essentials requirements for IT infrastructure v3.3, April 2026: the malware protection options, the MFA text and the passwordless list. Read from the text extraction of the PDF saved for briefing 283, searched for lookalike-related termsNational Cyber Security Centreaccessed 2026-10-10
  44. Reported byTwo characters open up a world of typosquatting opportunities in Chromium browsers, 10 October 2026, 11:15 UTC. A second reading of the write-up with no statement from Google or Microsoft. Read in fullThe Registeraccessed 2026-10-10

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.