CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

332 vulnerabilities with CWE-451
CVE-2026-18018 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Updater Component on Windows
CVSS 4.0
CVE-2026-18013 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-18010 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Passwords Implementation
CVSS 4.3
CVE-2026-18009 MEDIUM
Google Chrome - Improper Input Validation
CVSS 4.3
CVE-2026-18008 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Settings Implementation
CVSS 4.3
CVE-2026-18007 MEDIUM
Google Chrome on Android < 151.0.7922.72 - UI Spoofing via Crafted HTML Page in Input Implementation
CVSS 4.3
CVE-2026-18006 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Google Lens Inappropriate Implementation
CVSS 4.3
CVE-2026-18003 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-17998 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Malicious Extension
CVSS 4.3
CVE-2026-17983 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing in Global Media Controls via Crafted HTML Page
CVSS 4.3
CVE-2026-17980 LOW
Google Chrome on Android < 151.0.7922.72 - Cross-Origin Data Leak via UI Gesture Manipulation
CVSS 3.1
CVE-2026-17972 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-17965 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-17964 MEDIUM
Google Chrome on Android < 151.0.7922.72 - Domain Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-17958 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Crafted HTML Page in Views
CVSS 4.3
CVE-2026-17945 MEDIUM
Google Chrome < 151.0.7922.72 - UI Spoofing via Crafted HTML Page in Navigation
CVSS 4.3
CVE-2026-17941 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - URL Bar Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-17938 MEDIUM
Google Chrome on Android < 151.0.7922.72 - UI Spoofing via FullScreen Implementation
CVSS 4.3
CVE-2026-17915 MEDIUM
Google Chrome for Android < 151.0.7922.72 - UI Spoofing via Crafted HTML Page in WebView
CVSS 5.4
CVE-2026-17874 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2026-17747 MEDIUM
Google Chrome - Improper Input Validation
CVSS 4.2
CVE-2026-64735 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 6.5
CVE-2026-64730 MEDIUM
Apple Safari - Denial of Service
CVSS 6.5
CVE-2026-60658 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 7.5
CVE-2026-11925 LOW
Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
CVSS 2.7
Details
Vulnerabilities 332