Fallos del tipo CWE-451

389 resultados

Representação enganosa de informações críticas na interface

A aplicação apresenta informações de segurança ou avisos críticos de forma desorientadora, oculta ou disfarçada na UI, levando o usuário a tomar decisões perigosas sem compreender as consequências reais. O atacante explora isso para contornar decisões conscientes do usuário, como consentir a execução de código malicioso ou compartilhar dados sensíveis.

Ejemplo

Um navegador que exibe um aviso de certificado inválido em texto pequeno e cinzento no rodapé da página, enquanto mantém o resto do site completamente funcional e destacado, fazendo o usuário ignorar o risco e prosseguir. Ou um app que solicita permissão de câmera com a frase 'Necessário para melhor experiência' escondida em letras minúsculas, sem deixar claro que gravará vídeo.

Cómo mitigar

Deixe avisos e informações críticas de segurança visíveis, legíveis e sem ambiguidade: use cores de contraste alto, fonte adequada, posicionamento central, e linguagem clara. Exija confirmação explícita do usuário antes de ações perigosas e mostre exatamente o que será feito — nunca ocultando ou minimizando os riscos na apresentação.

CVE-2026-13984MEDIUMIncorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTMEPSS 0.2%CVE-2026-2316MEDIUMInsufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a craEPSS 0.2%CVE-2026-11175HIGHIncorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a EPSS 0.2%CVE-2026-2318MEDIUMInappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to eEPSS 0.2%CVE-2026-11172HIGHIncorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing EPSS 0.2%CVE-2026-10984MEDIUMInappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoEPSS 0.2%CVE-2026-2322MEDIUMInappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2026-53829HIGHOpenClaw < 2026.5.18 - Command Truncation in Exec Approval DisplayEPSS 0.2%CVE-2026-14114HIGHInappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoEPSS 0.2%CVE-2026-2323MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a craEPSS 0.2%CVE-2026-87507MEDIUMUI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UEPSS 0.2%CVE-2026-17941MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contentEPSS 0.2%CVE-2025-46311HIGHAn inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS EPSS 0.2%CVE-2026-79284MEDIUMUI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2025-13082MEDIUMDrupal core - Moderately critical - Defacement - SA-CORE-2025-007EPSS 0.2%CVE-2026-13842MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contentEPSS 0.2%CVE-2026-11107MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a craEPSS 0.2%CVE-2025-8583MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2025-31266MEDIUMA spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5,EPSS 0.2%CVE-2026-48851LOWPuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxyEPSS 0.2%