Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled Unicode glyphs, which allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
No PoCs from references.
- https://github.com/JasonLOU/security
- https://github.com/aghorler/sic-a1
- https://github.com/numirias/security