Fallos del tipo CWE-451

387 resultados

Representação enganosa de informações críticas na interface

A aplicação apresenta informações de segurança ou avisos críticos de forma desorientadora, oculta ou disfarçada na UI, levando o usuário a tomar decisões perigosas sem compreender as consequências reais. O atacante explora isso para contornar decisões conscientes do usuário, como consentir a execução de código malicioso ou compartilhar dados sensíveis.

Ejemplo

Um navegador que exibe um aviso de certificado inválido em texto pequeno e cinzento no rodapé da página, enquanto mantém o resto do site completamente funcional e destacado, fazendo o usuário ignorar o risco e prosseguir. Ou um app que solicita permissão de câmera com a frase 'Necessário para melhor experiência' escondida em letras minúsculas, sem deixar claro que gravará vídeo.

Cómo mitigar

Deixe avisos e informações críticas de segurança visíveis, legíveis e sem ambiguidade: use cores de contraste alto, fonte adequada, posicionamento central, e linguagem clara. Exija confirmação explícita do usuário antes de ações perigosas e mostre exatamente o que será feito — nunca ocultando ou minimizando os riscos na apresentação.

CVE-2025-21262MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2024-9163LOWUser Interface (UI) Misrepresentation of Critical Information in GitLabEPSS 0.4%CVE-2024-0805MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via aEPSS 0.4%CVE-2024-5698MEDIUMBy manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This coulEPSS 0.4%CVE-2025-8043CRITICALIncorrect URL truncationEPSS 0.4%CVE-2025-0451MEDIUMInappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engEPSS 0.4%CVE-2022-22762MEDIUMUnder certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This coEPSS 0.4%CVE-2026-9106MEDIUMUI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screenEPSS 0.4%CVE-2026-45488MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2024-52276HIGHPDF Document Spoofing in DocuSignEPSS 0.4%CVE-2026-40416MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.3%CVE-2026-79176MEDIUMUI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtainEPSS 0.3%CVE-2026-0906CRITICALIncorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (UREPSS 0.3%CVE-2026-17792MEDIUMInappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2026-17793MEDIUMInappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofingEPSS 0.3%CVE-2024-23708CRITICALIn multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has bEPSS 0.3%CVE-2024-6610MEDIUMForm validation popups could block exiting full-screen modeEPSS 0.3%CVE-2025-0435MEDIUMInappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2024-51749LOWElement's thumbnails can be abused to misrepresent the content of an attachmentEPSS 0.3%CVE-2026-45064LOWSymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingEPSS 0.3%