VYPR

CWE-451

User Interface (UI) Misrepresentation of Critical Information

ClassDraft

Description

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-154 · CAPEC-163 · CAPEC-164 · CAPEC-173 · CAPEC-98

CVEs mapped to this weakness (386)

page 10 of 20
  • CVE-2026-0385MedMar 16, 2026
    risk 0.33cvss 5.0epss 0.00

    Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

  • CVE-2026-87597MedSep 9, 2026
    risk 0.31cvss 4.8epss 0.00

    UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low)

  • CVE-2026-18622MedAug 13, 2026
    risk 0.31cvss 4.7epss 0.00

    Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual…

  • CVE-2026-14154MedJun 30, 2026
    risk 0.31cvss 4.8epss 0.00

    Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

  • CVE-2026-8565MedMay 14, 2026
    risk 0.31cvss 4.7epss 0.00

    Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-34258MedMay 12, 2026
    risk 0.31cvss 4.7epss 0.00

    SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This…

  • CVE-2026-44659MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the actual registrable domain (eTLD+1). As a result, an attacker can craft extremely…

  • CVE-2025-29796MedApr 4, 2025
    risk 0.31cvss 4.7epss 0.01

    User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-38082MedJun 20, 2024
    risk 0.31cvss 4.7epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2016-9473MedMar 28, 2017
    risk 0.31cvss 4.7epss 0.02

    Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.

  • CVE-2026-39309MedMay 20, 2026
    risk 0.29cvss 5.5epss 0.00

    Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading…

  • CVE-2026-87567MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)

  • CVE-2026-86853MedSep 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.

  • CVE-2026-84356MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-84137MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-79284MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79233MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79098MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79022MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79009MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)