VYPR

CWE-451

User Interface (UI) Misrepresentation of Critical Information

ClassDraft

Description

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-154 · CAPEC-163 · CAPEC-164 · CAPEC-173 · CAPEC-98

CVEs mapped to this weakness (347)

page 7 of 18
  • CVE-2026-33119MedApr 10, 2026
    risk 0.35cvss 5.4epss 0.00

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-5895MedApr 8, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)

  • CVE-2026-26320MedFeb 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only the first 240 characters of the message,…

  • CVE-2026-2322MedFeb 11, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0904MedJan 20, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-0901MedJan 20, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-14020MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct…

  • CVE-2025-64667MedDec 9, 2025
    risk 0.35cvss 5.3epss 0.01

    User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-12435MedNov 10, 2025
    risk 0.35cvss 5.4epss 0.00

    Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-9867MedSep 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-9865MedSep 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-47964MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-39730MedJun 28, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2025-3074MedApr 2, 2025
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2025-3073MedApr 2, 2025
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2025-3072MedApr 2, 2025
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2025-21259MedFeb 11, 2025
    risk 0.35cvss 5.3epss 0.01

    Microsoft Outlook Spoofing Vulnerability

  • CVE-2025-21253MedFeb 6, 2025
    risk 0.35cvss 5.3epss 0.01

    Microsoft Edge for IOS and Android Spoofing Vulnerability

  • CVE-2025-21262MedJan 24, 2025
    risk 0.35cvss 5.4epss 0.00

    User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network

  • CVE-2024-55896MedJan 3, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.