
Google has blocked unauthorized HTTPS certificates in Chrome after attackers hijacked infrastructure serving three country-code domain namespaces, affecting Google properties and other organizations’ websites.
The attacks targeted .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa, potentially putting any domain using those suffixes at risk.
Google’s Chrome Secure Web and Networking Team said it became aware of the incidents last week. Attackers modified authoritative DNS records and obtained HTTPS certificates for several Google domains and domains belonging to other organizations.
Country-code top-level domains underpin websites associated with particular countries and territories. A compromise at this level can threaten domains belonging to multiple unrelated organizations, extending the impact beyond a single website owner.
Google emphasized that its own systems were not compromised and said it had no reason to believe the certificate authorities that issued the affected certificates had acted improperly.
HTTPS certificates help browsers authenticate websites and establish encrypted connections. Control over a domain’s DNS can allow an attacker to demonstrate apparent ownership to a certificate authority and obtain a certificate without the legitimate owner’s permission.
Combined with redirected traffic, such certificates could enable convincing website impersonation. Google’s announcement does not establish whether the attackers used them to intercept communications or steal user data.
Emergency certificate blocking
Google initially blocked the unauthorized certificates covering its own properties through CRLSets, Chrome’s mechanism for rapidly rejecting certificates during security incidents. It also worked with the issuing certificate authorities to revoke them, extending mitigation beyond Chrome.
Subsequent analysis of Certificate Transparency (CT) logs revealed certificates for additional organizations believed to have been affected by the same attacks, including major global brands and widely used online services.
Google proactively blocked those certificates in Chrome and, where possible, notified the affected organizations. The announcement does not identify those organizations, provide a certificate count, or attribute the attacks.
Chrome users receive the protection automatically and do not need to take action. However, Google cautioned that its investigation may not have identified every affected domain and that Chrome’s interventions cannot reliably protect users of other clients.
Protecting domains after a hijack
Google urged domain owners to monitor CT logs across their entire portfolio, including parked domains and regional properties. These public records disclose certificate issuance and can help organizations quickly spot certificates they did not authorize.
Owners of .gh, .sl, and .as domains should specifically review recent entries for unexpected issuance.
The company also recommended restrictive Certification Authority Authorization (CAA) DNS records, including ACME account bindings and limits on permitted validation methods.
CAA policies specify which authorities may issue certificates. They cannot stop issuance during an active DNS hijack, but restoring restrictive policies after regaining control can prevent attackers from obtaining additional certificates using previously cached domain-control validation.
Google said it will continue pursuing shorter certificate lifetimes and reduced validation reuse through its Chrome Root Program and new Chrome Quantum-resistant Root Program. For affected domain owners, the immediate priorities are reviewing issuance records and tightening certificate authorization after DNS control is restored.







Leave a Reply