...which is, in fact, exactly how this bug was exposed.
Modern browsers don't support UTF-7 any more after a number of XSS attacks relying on inserting UTF-7 encoded script elements which then cause the document to be sniffed as UTF-7.
The only place UTF-7 is still widely used is in email clients.