Falhas do tipo CWE-451

389 resultados

Má representação de informações críticas na interface

A aplicação exibe informações de segurança críticas de forma enganosa, confusa ou incompleta na interface do usuário. Isso leva o usuário a tomar decisões perigosas — como confiar em dados falsos, ignorar avisos reais ou autorizar operações maliciosas — porque a UI não comunica o risco com clareza.

Exemplo

Um navegador que mostra um aviso de certificado SSL inválido em letras minúsculas cinzentas no rodapé da página, enquanto a barra de endereço verde continua exibindo cadeado. Ou um aplicativo bancário que não deixa evidente se uma transação é reversível ou definitiva, levando o usuário a confirmar uma transferência irreversível sem entender as consequências.

Como mitigar

Destaque informações críticas (avisos, confirmações, mudanças de estado) com contraste visual alto, ícones claros e mensagens em linguagem simples. Implemente confirmações explícitas para operações irreversíveis e testes de usabilidade com usuários reais para validar se entendem os riscos antes de agir.

CVE-2026-93386MEDIUMUI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spEPSS 0.3%CVE-2026-79173MEDIUMUI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted EPSS 0.3%CVE-2026-79180MEDIUMUI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeEPSS 0.3%CVE-2026-34258MEDIUMContent Spoofing vulnerability in SAPUI5 (Search UI)EPSS 0.2%CVE-2025-9183MEDIUMSpoofing issue in the Address Bar componentEPSS 0.2%CVE-2025-12435MEDIUMIncorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2025-31951HIGHHCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerabilityEPSS 0.2%CVE-2026-17913MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofiEPSS 0.2%CVE-2026-13867MEDIUMInappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2026-14127MEDIUMInappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2026-13978MEDIUMInsufficient policy enforcement in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2026-13916MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofiEPSS 0.2%CVE-2026-13941MEDIUMInappropriate implementation in SiteSettings in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spooEPSS 0.2%CVE-2026-13837MEDIUMInappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 0.2%CVE-2026-14141MEDIUMIncorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to performEPSS 0.2%CVE-2026-13981MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofiEPSS 0.2%CVE-2026-14410MEDIUMInappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2026-13979MEDIUMInappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a craftedEPSS 0.2%CVE-2026-14130MEDIUMIncorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTMLEPSS 0.2%CVE-2026-14042MEDIUMInappropriate implementation in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing vEPSS 0.2%