Weaknesses of type CWE-451

387 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2025-21262MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2024-9163LOWUser Interface (UI) Misrepresentation of Critical Information in GitLabEPSS 0.4%CVE-2024-0805MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via aEPSS 0.4%CVE-2024-5698MEDIUMBy manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This coulEPSS 0.4%CVE-2025-8043CRITICALIncorrect URL truncationEPSS 0.4%CVE-2025-0451MEDIUMInappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engEPSS 0.4%CVE-2022-22762MEDIUMUnder certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This coEPSS 0.4%CVE-2026-9106MEDIUMUI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screenEPSS 0.4%CVE-2026-45488MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2024-52276HIGHPDF Document Spoofing in DocuSignEPSS 0.4%CVE-2026-40416MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.3%CVE-2026-79176MEDIUMUI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtainEPSS 0.3%CVE-2026-0906CRITICALIncorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (UREPSS 0.3%CVE-2026-17792MEDIUMInappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2026-17793MEDIUMInappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofingEPSS 0.3%CVE-2024-23708CRITICALIn multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has bEPSS 0.3%CVE-2024-6610MEDIUMForm validation popups could block exiting full-screen modeEPSS 0.3%CVE-2025-0435MEDIUMInappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2024-51749LOWElement's thumbnails can be abused to misrepresent the content of an attachmentEPSS 0.3%CVE-2026-45064LOWSymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingEPSS 0.3%