{"success":true,"data":{"id":"href-text-bidi-override","label":"Bidi override in anchor text — reversed CTA URL spoofing","description":"The inner text of an `<a>` tag contains a Unicode bidi-control character. Dangerous variant: an anchor like `<a href=\"https://attacker/login\">https://\\u202Emoc.laypap/signin</a>` renders in the mail client as `https://paypal.com/signin` — a sighted user sees a convincing PayPal link and clicks through to the attacker. The detection is scoped strictly to anchor INNER content (not the href attribute). Fourth member of the bidi-abuse family alongside the From header, subject, and attachment checks.","tier":"danger","category":"other","isThin":false}}