Weaknesses of type CWE-451

387 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2026-45064LOWSymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingEPSS 0.3%CVE-2026-9110MEDIUMInappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renEPSS 0.3%CVE-2024-8909MEDIUMInappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a craEPSS 0.3%CVE-2026-28964HIGHAn inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOSEPSS 0.3%CVE-2026-18487MEDIUMEpiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()EPSS 0.3%CVE-2025-3523MEDIUMUser Interface (UI) Misrepresentation of attachment URLEPSS 0.3%CVE-2026-17747MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had EPSS 0.3%CVE-2025-62224MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.3%CVE-2026-33119MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.3%CVE-2026-2634CRITICALSpoofed web content presented under trusted domains using scripted navigation on Firefox iOSEPSS 0.3%CVE-2025-7021MEDIUMOpenAI Operator - API Spoofing through Locking Operator on FullScreenEPSS 0.3%CVE-2026-3861HIGHLINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly EPSS 0.3%CVE-2026-8964HIGHSpoofing issue in the Popup Blocker componentEPSS 0.3%CVE-2026-17840MEDIUMIncorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafteEPSS 0.3%CVE-2025-32371MEDIUMUnexpected external content may be displayed in DNN ImageHandlerEPSS 0.3%CVE-2026-17782MEDIUMIncorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of thEPSS 0.3%CVE-2025-9867MEDIUMInappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofinEPSS 0.3%CVE-2025-3074MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a craEPSS 0.3%CVE-2025-3072MEDIUMInappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engageEPSS 0.3%CVE-2025-3073MEDIUMInappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage inEPSS 0.3%