CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

332 vulnerabilities with CWE-451
CVE-2026-16403 MEDIUM
Mozilla Firefox Address Bar - Spoofing
CVSS 6.5
CVE-2026-45150 MEDIUM
Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing
CVE-2026-48760 MEDIUM
Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
CVSS 6.1
CVE-2026-45064 MEDIUM
Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
CVSS 6.1
CVE-2026-13356 MEDIUM
Interrupted navigation could allow address bar origin spoofing in Firefox for iOS
CVSS 6.3
CVE-2026-45488 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVSS 5.4
CVE-2026-14410 MEDIUM
Google Chrome < 150.0.7871.46 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-14404 MEDIUM
Google Chrome < 150.0.7871.46 - UI Spoofing via Crafted PDF File
CVSS 6.5
CVE-2026-14381 MEDIUM
Google Chrome < 150.0.7871.46 - UI Spoofing via WebAppInstalls
CVSS 6.5
CVE-2026-14154 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Malicious Extension
CVSS 4.8
CVE-2026-14153 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 5.3
CVE-2026-14144 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 4.2
CVE-2026-14143 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Passwords Security UI
CVSS 4.3
CVE-2026-14142 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2026-14141 MEDIUM
Chrome < 150.0.7871.47 - Domain Spoofing via Document Picture-in-Picture
CVSS 4.3
CVE-2026-14139 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via TabStrip
CVSS 4.2
CVE-2026-14138 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 4.2
CVE-2026-14136 MEDIUM
Google Chrome for iOS < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2026-14134 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Autofill
CVSS 4.3
CVE-2026-14132 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via WebXR
CVSS 5.4
CVE-2026-14130 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Omnibox Security Indicator
CVSS 4.3
CVE-2026-14129 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via PreviewTab
CVSS 4.2
CVE-2026-14128 MEDIUM
Google Chrome for iOS < 150.0.7871.47 - URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2026-14127 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Printing
CVSS 4.3
CVE-2026-14126 MEDIUM
Google Chrome < 150.0.7871.47 - Domain Spoofing via Crafted HTML Page
CVSS 4.3
Details
Vulnerabilities 332