> 82 pairs are pixel-identical
> a string like “аpple.com” with Cyrillic а (U+0430) is pixel-identical to “apple.com” in 40+ fonts. The user, the browser’s address bar, and any visual review process all see the same pixels. This is not theoretical. It is a measured property of the font files shipping on every Mac.
Current implementations of "Computer Use" Agentic AI tools mostly use visuals -- screenshotting of a computer screen and interpreting it.
These pixel-dentical character pairs will be a straight failure mode for those automations and could possibly be a threat vector if crafted well.
I don’t think a human could tell the difference either. This will make phishing emails much more effective.