VYPR

CWE-451

User Interface (UI) Misrepresentation of Critical Information

ClassDraft

Description

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-154 · CAPEC-163 · CAPEC-164 · CAPEC-173 · CAPEC-98

CVEs mapped to this weakness (347)

page 3 of 18
  • CVE-2026-17819MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17793MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17792MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-16403MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-14014MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14002MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13996MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13988MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13985MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13892MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-11227MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)

  • CVE-2026-11225MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)

  • CVE-2026-11222MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11215MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

  • CVE-2026-11019MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-11001MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-42891MedMay 12, 2026
    risk 0.42cvss 6.5epss 0.00

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-3861MedApr 16, 2026
    risk 0.42cvss 6.5epss 0.00

    LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become…

  • CVE-2026-5905MedApr 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-3889MedMar 24, 2026
    risk 0.42cvss 6.5epss 0.00

    Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.