Weaknesses of type CWE-451

389 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2026-17838MEDIUMIncorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing EPSS 0.3%CVE-2026-32971HIGHOpenClaw < 2026.3.11 - Node-Host Approval UI Mismatch Allows Execution of Unintended CommandsEPSS 0.3%CVE-2026-17812MEDIUMInappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing EPSS 0.3%CVE-2026-13989MEDIUMInappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer EPSS 0.3%CVE-2026-79022MEDIUMUI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerinEPSS 0.3%CVE-2025-11720HIGHSpoofing risk in Android custom tabsEPSS 0.3%CVE-2026-14404MEDIUMInappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafteEPSS 0.3%CVE-2026-14153MEDIUMInappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in speEPSS 0.3%CVE-2026-11019MEDIUMInappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-87445MEDIUMUI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML paEPSS 0.3%CVE-2026-14381MEDIUMIncorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a craftEPSS 0.3%CVE-2025-9865MEDIUMInappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user toEPSS 0.3%CVE-2025-10290MEDIUMOpening links via the contextual menu in Focus for iOS would not update the toolbar UI correctly, allowing attackers to spoof websitesEPSS 0.3%CVE-2026-1658MEDIUMContent spoofing vulnerability discovered in OpenText™ Directory ServicesEPSS 0.3%CVE-2026-79108MEDIUMUI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveEPSS 0.3%CVE-2026-79173MEDIUMUI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted EPSS 0.3%CVE-2026-79250MEDIUMUI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTMLEPSS 0.3%CVE-2026-79204MEDIUMUI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a craftedEPSS 0.3%CVE-2026-78912MEDIUMUI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML paEPSS 0.3%CVE-2026-78974MEDIUMUI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerinEPSS 0.3%