Falhas do tipo CWE-451

389 resultados

Má representação de informações críticas na interface

A aplicação exibe informações de segurança críticas de forma enganosa, confusa ou incompleta na interface do usuário. Isso leva o usuário a tomar decisões perigosas — como confiar em dados falsos, ignorar avisos reais ou autorizar operações maliciosas — porque a UI não comunica o risco com clareza.

Exemplo

Um navegador que mostra um aviso de certificado SSL inválido em letras minúsculas cinzentas no rodapé da página, enquanto a barra de endereço verde continua exibindo cadeado. Ou um aplicativo bancário que não deixa evidente se uma transação é reversível ou definitiva, levando o usuário a confirmar uma transferência irreversível sem entender as consequências.

Como mitigar

Destaque informações críticas (avisos, confirmações, mudanças de estado) com contraste visual alto, ícones claros e mensagens em linguagem simples. Implemente confirmações explícitas para operações irreversíveis e testes de usabilidade com usuários reais para validar se entendem os riscos antes de agir.

CVE-2026-81267MEDIUMStalled popup navigation could allow address bar origin spoofing in Firefox for iOSEPSS 0.2%CVE-2026-87559MEDIUMUI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elemeEPSS 0.2%CVE-2024-11919MEDIUMInappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing EPSS 0.2%CVE-2024-13178MEDIUMInappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crEPSS 0.2%CVE-2025-13107MEDIUMInappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2026-3889MEDIUMSpoofing issue in ThunderbirdEPSS 0.2%CVE-2025-12728MEDIUMInappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user tEPSS 0.2%CVE-2025-11212MEDIUMInappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to eEPSS 0.2%CVE-2026-9078MEDIUMFirefox iOS RTL Domain Rendering Issue in Link PreviewEPSS 0.2%CVE-2026-17915MEDIUMInappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing EPSS 0.2%CVE-2026-14144MEDIUMIncorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific EPSS 0.2%CVE-2026-13993MEDIUMIncorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in EPSS 0.2%CVE-2026-14138MEDIUMInappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a EPSS 0.2%CVE-2026-14139MEDIUMInappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2026-79283MEDIUMUI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML pEPSS 0.2%CVE-2026-14026MEDIUMIncorrect security UI in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in speciEPSS 0.2%CVE-2026-16403MEDIUMSpoofing issue in the Address Bar componentEPSS 0.2%CVE-2026-14030MEDIUMInappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user toEPSS 0.2%CVE-2026-13998MEDIUMIncorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2026-14129MEDIUMInappropriate implementation in PreviewTab in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a userEPSS 0.2%