VYPR

CWE-451

User Interface (UI) Misrepresentation of Critical Information

ClassDraft

Description

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-154 · CAPEC-163 · CAPEC-164 · CAPEC-173 · CAPEC-98

CVEs mapped to this weakness (386)

page 5 of 20
  • CVE-2025-7021MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with…

  • CVE-2025-5986MedJun 11, 2025
    risk 0.42cvss 6.5epss 0.01

    A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using…

  • CVE-2025-5066MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-5065MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-29825MedMay 2, 2025
    risk 0.42cvss 6.5epss 0.01

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-4086MedApr 29, 2025
    risk 0.42cvss 6.5epss 0.00

    A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was…

  • CVE-2025-3523MedApr 15, 2025
    risk 0.42cvss 6.4epss 0.00

    When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into…

  • CVE-2025-0435MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-21314MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.01

    Windows SmartScreen Spoofing Vulnerability

  • CVE-2024-7529MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.01

    The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2023-7011MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-4950MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-50938MedFeb 2, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further…

  • CVE-2023-0700MedFeb 7, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-0130MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-45404MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Through a series of popup and window.print() calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5,…

  • CVE-2022-34479MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. *This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This…

  • CVE-2022-3313MedNov 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-11213MedNov 6, 2025
    risk 0.41cvss 6.3epss 0.00

    Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-11212MedNov 6, 2025
    risk 0.41cvss 6.3epss 0.00

    Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)