Weaknesses of type CWE-451

389 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2026-14030MEDIUMInappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user toEPSS 0.2%CVE-2026-13998MEDIUMIncorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2026-14144MEDIUMIncorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific EPSS 0.2%CVE-2026-16403MEDIUMSpoofing issue in the Address Bar componentEPSS 0.2%CVE-2026-17915MEDIUMInappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing EPSS 0.2%CVE-2025-3859MEDIUMFirefox Focus elide URL allows address bar spoofingEPSS 0.2%CVE-2024-52270HIGHPDF Document Spoofing in DropBox Sign(HelloSign)EPSS 0.2%CVE-2024-7021MEDIUMInappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofingEPSS 0.2%CVE-2026-92069MEDIUMSpoofing issue in the DOM: Navigation componentEPSS 0.2%CVE-2026-17972MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofiEPSS 0.2%CVE-2026-5880MEDIUMInsufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-17965MEDIUMIncorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via EPSS 0.2%CVE-2026-17964MEDIUMIncorrect security UI in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crEPSS 0.2%CVE-2026-5882MEDIUMIncorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 0.2%CVE-2026-5878MEDIUMIncorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML pEPSS 0.2%CVE-2026-17945MEDIUMInsufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.2%CVE-2026-17958MEDIUMInappropriate implementation in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a craftedEPSS 0.2%CVE-2026-7935MEDIUMInappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafteEPSS 0.2%CVE-2026-79233MEDIUMUI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via EPSS 0.2%CVE-2026-12458LOWInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage EPSS 0.2%