Fallos del tipo CWE-451

389 resultados

Representação enganosa de informações críticas na interface

A aplicação apresenta informações de segurança ou avisos críticos de forma desorientadora, oculta ou disfarçada na UI, levando o usuário a tomar decisões perigosas sem compreender as consequências reais. O atacante explora isso para contornar decisões conscientes do usuário, como consentir a execução de código malicioso ou compartilhar dados sensíveis.

Ejemplo

Um navegador que exibe um aviso de certificado inválido em texto pequeno e cinzento no rodapé da página, enquanto mantém o resto do site completamente funcional e destacado, fazendo o usuário ignorar o risco e prosseguir. Ou um app que solicita permissão de câmera com a frase 'Necessário para melhor experiência' escondida em letras minúsculas, sem deixar claro que gravará vídeo.

Cómo mitigar

Deixe avisos e informações críticas de segurança visíveis, legíveis e sem ambiguidade: use cores de contraste alto, fonte adequada, posicionamento central, e linguagem clara. Exija confirmação explícita do usuário antes de ações perigosas e mostre exatamente o que será feito — nunca ocultando ou minimizando os riscos na apresentação.

CVE-2026-87635MEDIUMUI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML pEPSS 0.2%CVE-2026-87496MEDIUMUI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI EPSS 0.2%CVE-2024-55896MEDIUMIBM PowerHA SystemMirror for i clickjackingEPSS 0.2%CVE-2024-39730MEDIUMIBM Datacap clickjackingEPSS 0.2%CVE-2025-8364MEDIUMAddress bar spoofing using an blob URI on Firefox for AndroidEPSS 0.2%CVE-2026-13356MEDIUMInterrupted navigation could allow address bar origin spoofing in Firefox for iOSEPSS 0.2%CVE-2026-13982LOWIncorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2026-2320MEDIUMInappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2025-11208MEDIUMInappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in spEPSS 0.2%CVE-2026-14132MEDIUMInappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a craftedEPSS 0.2%CVE-2026-14128MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contentEPSS 0.2%CVE-2026-14077MEDIUMInappropriate implementation in Select in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of theEPSS 0.2%CVE-2026-14136MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perEPSS 0.2%CVE-2026-11001MEDIUMInappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2026-14031MEDIUMInappropriate implementation in File Input in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crEPSS 0.2%CVE-2026-14123MEDIUMIncorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of thEPSS 0.2%CVE-2026-14143MEDIUMIncorrect security UI in Passwords in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a craEPSS 0.2%CVE-2025-11213MEDIUMInappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user toEPSS 0.2%CVE-2026-87484MEDIUMUI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UIEPSS 0.2%CVE-2024-6429MEDIUMContent Spoofing in Multiple WSO2 Products via Error Message InjectionEPSS 0.2%