Falhas do tipo CWE-451

389 resultados

Má representação de informações críticas na interface

A aplicação exibe informações de segurança críticas de forma enganosa, confusa ou incompleta na interface do usuário. Isso leva o usuário a tomar decisões perigosas — como confiar em dados falsos, ignorar avisos reais ou autorizar operações maliciosas — porque a UI não comunica o risco com clareza.

Exemplo

Um navegador que mostra um aviso de certificado SSL inválido em letras minúsculas cinzentas no rodapé da página, enquanto a barra de endereço verde continua exibindo cadeado. Ou um aplicativo bancário que não deixa evidente se uma transação é reversível ou definitiva, levando o usuário a confirmar uma transferência irreversível sem entender as consequências.

Como mitigar

Destaque informações críticas (avisos, confirmações, mudanças de estado) com contraste visual alto, ícones claros e mensagens em linguagem simples. Implemente confirmações explícitas para operações irreversíveis e testes de usabilidade com usuários reais para validar se entendem os riscos antes de agir.

CVE-2026-14030MEDIUMInappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user toEPSS 0.2%CVE-2026-13998MEDIUMIncorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2026-14144MEDIUMIncorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific EPSS 0.2%CVE-2026-16403MEDIUMSpoofing issue in the Address Bar componentEPSS 0.2%CVE-2026-17915MEDIUMInappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing EPSS 0.2%CVE-2025-3859MEDIUMFirefox Focus elide URL allows address bar spoofingEPSS 0.2%CVE-2024-52270HIGHPDF Document Spoofing in DropBox Sign(HelloSign)EPSS 0.2%CVE-2024-7021MEDIUMInappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofingEPSS 0.2%CVE-2026-92069MEDIUMSpoofing issue in the DOM: Navigation componentEPSS 0.2%CVE-2026-17972MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofiEPSS 0.2%CVE-2026-5880MEDIUMInsufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-17965MEDIUMIncorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via EPSS 0.2%CVE-2026-17964MEDIUMIncorrect security UI in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crEPSS 0.2%CVE-2026-5882MEDIUMIncorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 0.2%CVE-2026-5878MEDIUMIncorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML pEPSS 0.2%CVE-2026-17945MEDIUMInsufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.2%CVE-2026-17958MEDIUMInappropriate implementation in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a craftedEPSS 0.2%CVE-2026-7935MEDIUMInappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafteEPSS 0.2%CVE-2026-79233MEDIUMUI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via EPSS 0.2%CVE-2026-12458LOWInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage EPSS 0.2%