CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

230 vulnerabilities with CWE-451
CVE-2026-53829 HIGH
OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
CVSS 8.0
CVE-2026-45650 MEDIUM
Microsoft Bing Search Spoofing Vulnerability
CVSS 4.3
CVE-2026-11300 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-11294 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-11286 MEDIUM
Google Chrome - Improper Input Validation
CVSS 4.3
CVE-2026-11285 MEDIUM
Chrome for iOS < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-11254 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-11245 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Payments
CVSS 4.3
CVE-2026-11232 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via TabGroups
CVSS 5.4
CVE-2026-11228 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via File Input
CVSS 4.3
CVE-2026-11227 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Tab Hover Card
CVSS 6.5
CVE-2026-11225 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Crafted Domain Name
CVSS 6.5
CVE-2026-11222 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Tab Strip Security UI
CVSS 6.5
CVE-2026-11216 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via File Input Security UI
CVSS 4.3
CVE-2026-11215 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Crafted Domain Name
CVSS 6.5
CVE-2026-11175 HIGH
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 8.8
CVE-2026-11172 HIGH
Google Chrome < 149.0.7827.53 - UI Spoofing via Contact Picker
CVSS 8.8
CVE-2026-11107 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-11019 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-11001 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Payments Implementation
CVSS 6.5
CVE-2026-10984 MEDIUM
Google Chrome < 149.0.7827.53 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2026-0096 HIGH
Google Android - User Interface (UI) Misrepresentation of Critical Information
CVSS 7.8
CVE-2026-0094 HIGH
Google Android - User Interface (UI) Misrepresentation of Critical Information
CVSS 7.8
CVE-2026-0093 HIGH
Google Android - User Interface (UI) Misrepresentation of Critical Information
CVSS 7.8
CVE-2026-0088 HIGH
Android - Local Privilege Escalation via Misleading UI in CertInstaller
CVSS 7.8
Details
Vulnerabilities 230