CWE-1007: Insufficient Visual Distinction of Homoglyphs Presented to User
The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.
4 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-27611 — base-x homograph attack allows Unicode lookalike characters to bypass validation.
- CVE-2026-48760 — Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
- CVE-2026-45064 — Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
- CVE-2025-0996 — Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker
Recently published
- CVE-2026-48760 — Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
- CVE-2026-45064 — Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
- CVE-2025-27611 — base-x homograph attack allows Unicode lookalike characters to bypass validation.
- CVE-2025-0996 — Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker