HomeSecurityCritical 0-Click vulnerability allows email account theft

Critical 0-Click vulnerability allows email account theft

A critical zero-click vulnerability allows attackers to take over online accountsby exploiting the way web applications handle international email addresses. The flaw is located in a technical discrepancy known as a “canonicalization mismatch” and affects systems password reset and , which are fundamental to modern online security.

0-Click email vulnerability

According to NullSecurityX, the attack requires no interaction from the victim. An attacker can gain complete control of an account simply by requesting a password reset using a specially crafted email address that looks identical to the victim's. This means there is no need to attempt a phishing attack or trick the user into clicking a malicious link.

See also: CISA: Race Condition Vulnerability in Linux Kernel

The vulnerability stems from the interaction between Unicode, which allows characters from various languages ​​in domain names (IDNs), and Punycode, the system that converts these characters to the standard ASCII format used by the internet infrastructure.

0-Click Vulnerability via Punycode

Attackers can register a domain using Unicode characters that are indistinguishable from standard characters, such as a Cyrillic 'o' instead of a Latin 'o'. According to a technical analysis of the vulnerability, the attack occurs when the backend of a web application processes a password reset. For example, an attacker can request a password reset for “[victim@gmail.com]” but submit the address using a “full-width” 'm' (gmail.com). The application's validation logic or front-end may fail to distinguish between the legitimate address and the visually similar address. Thus, it may approve the password reset request.

However, when the email system sends the reset link, it correctly routes it to the Punycode version of the domain, which is controlled by the attacker (e.g., xn--…). The attacker receives the privileged link and ultimately takes control of the victim's account. The legitimate user understands nothing.

See also: Hackers exploit critical vulnerability in SAP S/4HANA

Critical 0-Click vulnerability allows email account theft

The “0-click” nature of this vulnerability is what makes the threat so serious. The breach is not the result of user error but a fundamental flaw in the way different layers of an application (from the user interface and validation rules to the database and mail servers) handle email addresses. The end user has no self-protection mechanism, since the attack occurs entirely on the application side.

Each component may interpret Unicode and Punycode versions differently, creating a loophole that attackers can exploit.

This means that the responsibility falls solely on developers and service providers, who are called upon to fundamentally rethink the way in which address normalization is done.

"The result is that two addresses that appear identical to humans can be treated as different strings by the mail transport system," the NullSecurityX research paper states.

Since email is often used to regain access to countless other online services, a breach can have dire consequences. Experts are urging developers to review and strengthen their authentication systems immediately.

See also: Zero-day in Sitecore configuration is actively exploited

Critical 0-Click vulnerability allows email account theft

It is essential to implement consistent normalization of email addresses across all system components, using robust validation libraries that understand Unicode confusables, and ensuring that database searches are not vulnerable to these visual tricks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This vulnerability highlights a deeper problem that is often overlooked: the internet ecosystem is based on layers of software that don’t always have consistent validation rules. When the UI sees something different from the backend, a gap is created that attackers exploit with remarkable ease. We’re not talking about traditional phishing here, but something more dangerous: an invisible distortion of how systems perceive a user’s identity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS