A critical zero-click vulnerability allows attackers to take over online accountsby exploiting the way web applications handle international email addresses. The flaw is located in a technical discrepancy known as a “canonicalization mismatch” and affects systems password reset and , which are fundamental to modern online security.

According to NullSecurityX, the attack requires no interaction from the victim. An attacker can gain complete control of an account simply by requesting a password reset using a specially crafted email address that looks identical to the victim's. This means there is no need to attempt a phishing attack or trick the user into clicking a malicious link.
See also: CISA: Race Condition Vulnerability in Linux Kernel
The vulnerability stems from the interaction between Unicode, which allows characters from various languages in domain names (IDNs), and Punycode, the system that converts these characters to the standard ASCII format used by the internet infrastructure.
0-Click Vulnerability via Punycode
Attackers can register a domain using Unicode characters that are indistinguishable from standard characters, such as a Cyrillic 'o' instead of a Latin 'o'. According to a technical analysis of the vulnerability, the attack occurs when the backend of a web application processes a password reset. For example, an attacker can request a password reset for “[victim@gmail.com]” but submit the address using a “full-width” 'm' (gmail.com). The application's validation logic or front-end may fail to distinguish between the legitimate address and the visually similar address. Thus, it may approve the password reset request.
However, when the email system sends the reset link, it correctly routes it to the Punycode version of the domain, which is controlled by the attacker (e.g., xn--…). The attacker receives the privileged link and ultimately takes control of the victim's account. The legitimate user understands nothing.
See also: Hackers exploit critical vulnerability in SAP S/4HANA

The “0-click” nature of this vulnerability is what makes the threat so serious. The breach is not the result of user error but a fundamental flaw in the way different layers of an application (from the user interface and validation rules to the database and mail servers) handle email addresses. The end user has no self-protection mechanism, since the attack occurs entirely on the application side.
Each component may interpret Unicode and Punycode versions differently, creating a loophole that attackers can exploit.
This means that the responsibility falls solely on developers and service providers, who are called upon to fundamentally rethink the way in which address normalization is done.
"The result is that two addresses that appear identical to humans can be treated as different strings by the mail transport system," the NullSecurityX research paper states.
Since email is often used to regain access to countless other online services, a breach can have dire consequences. Experts are urging developers to review and strengthen their authentication systems immediately.
See also: Zero-day in Sitecore configuration is actively exploited

It is essential to implement consistent normalization of email addresses across all system components, using robust validation libraries that understand Unicode confusables, and ensuring that database searches are not vulnerable to these visual tricks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This vulnerability highlights a deeper problem that is often overlooked: the internet ecosystem is based on layers of software that don’t always have consistent validation rules. When the UI sees something different from the backend, a gap is created that attackers exploit with remarkable ease. We’re not talking about traditional phishing here, but something more dangerous: an invisible distortion of how systems perceive a user’s identity.
