Weaknesses of type CWE-451

389 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2025-14023LOWLINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user inteEPSS 0.2%CVE-2026-39309MEDIUMTrilium Notes: macOS TCC Bypass via Prompt SpoofingEPSS 0.2%CVE-2025-14019LOWLINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure EPSS 0.2%CVE-2026-11245MEDIUMInappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafEPSS 0.2%CVE-2026-11254MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2026-86853MEDIUMRepeated external URL scheme launches could potentially cause a denial of service in Firefox for iOSEPSS 0.2%CVE-2026-17980LOWInappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engaEPSS 0.2%CVE-2026-11222MEDIUMIncorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafteEPSS 0.2%CVE-2026-5898MEDIUMIncorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a craftEPSS 0.2%CVE-2026-87649MEDIUMUI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass EPSS 0.2%CVE-2026-13948LOWInsufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a EPSS 0.2%CVE-2026-13945LOWInsufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to iEPSS 0.2%CVE-2026-87583MEDIUMUI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via aEPSS 0.2%CVE-2026-44659MEDIUMZen Browser Mac - Address Bar Spoofing via Long SubdomainEPSS 0.2%CVE-2026-8564MEDIUMIncorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofEPSS 0.2%CVE-2026-20732LOWBIG-IP Configuration utility vulnerabilityEPSS 0.2%CVE-2026-11216MEDIUMIncorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specEPSS 0.2%CVE-2025-12446MEDIUMIncorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in speciEPSS 0.2%CVE-2026-3935MEDIUMIncorrect security UI in WebAppInstalls in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a craftEPSS 0.2%CVE-2026-5906MEDIUMIncorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the OEPSS 0.2%