Weaknesses of type CWE-451

386 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2022-26383MEDIUMWhen resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affectEPSS 0.7%CVE-2024-30055MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.6%CVE-2023-2941MEDIUMInappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install aEPSS 0.6%CVE-2026-45650MEDIUMMicrosoft Bing Search Spoofing VulnerabilityEPSS 0.6%CVE-2026-0391MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.6%CVE-2022-45404MEDIUMThrough a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing theEPSS 0.6%CVE-2022-2800MEDIUMSourceCodester Gym Management System clickjackingEPSS 0.6%CVE-2022-38163LOWA Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below. Drag and drop operatEPSS 0.6%CVE-2025-29796MEDIUMMicrosoft Edge for iOS Spoofing VulnerabilityEPSS 0.6%CVE-2025-5986MEDIUMUnsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// LinksEPSS 0.6%CVE-2021-27414MEDIUMUser interface misrepresentation of critical information in Hitachi ABB Power Grids Ellipse EAMEPSS 0.6%CVE-2023-0130MEDIUMInappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the EPSS 0.6%CVE-2026-33118MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.6%CVE-2026-64735MEDIUMAn inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOEPSS 0.5%CVE-2024-7529HIGHThe date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. EPSS 0.5%CVE-2025-30467MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4EPSS 0.5%CVE-2025-47963MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.5%CVE-2026-35429MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.5%CVE-2024-38093MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.5%CVE-2024-38082MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.5%