← Back
CWE-451

308 CVEs • Abstraction: Class

User Interface (UI) Misrepresentation of Critical Information

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Jun 17, 2026
Sep 3, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML pa...Show more
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)Show less
1Microsoft
1Windows 11 23h2
Jun 17, 2026
Aug 26, 2025
4.6 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction i...Show more
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.Show less
1Mozilla
1Firefox
Jun 17, 2026
Aug 19, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
1Mozilla
1Firefox
Jun 17, 2026
Aug 19, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
1Mozilla
1Firefox
Jun 17, 2026
Aug 19, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*...Show more
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 141.Show less
1Mozilla
1Firefox
Jun 17, 2026
Aug 19, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in Firefox 141.
1Microsoft
1Edge
Jun 17, 2026
Aug 12, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
1Google
1Chrome
Jun 17, 2026
Aug 7, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
1Apple
3Ipados
Iphone OsSafari
Jun 17, 2026
Jul 30, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.
-
-
Jun 17, 2026
Jul 25, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/...Show more
JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/account endpoint contains the value ROLE_USER. By manipulating the authorities parameter and changing its value to ROLE_ADMIN, the privilege is successfully escalated to an Admin level. This allowed the access to all admin-related functionalities in the application. NOTE: this is disputed by the Supplier because there is no privilege escalation in the context of the JHipster backend (the report only demonstrates that, after using JHipster to generate an application, one can make a non-functional admin screen visible in the front end of that application).Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jul 22, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.
1Microsoft
1Edge Chromium
Jun 17, 2026
Jul 11, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Microsoft
1Edge Chromium
Jun 17, 2026
Jul 11, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
1Openai
1Operator
Jun 17, 2026
Jul 10, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email address...Show more
Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser controls and a distracting element (like a cookie consent screen) to obscure fullscreen notifications, tricking the user into interacting with the malicious site.Show less
1Ibm
2Datacap
Datacap Navigator
Jun 17, 2026
Jun 28, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerab...Show more
IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.Show less
1Mozilla
1Thunderbird
Jun 17, 2026
Jun 11, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abu...Show more
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.Show less
1Google
1Chrome
Jun 17, 2026
May 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page....Show more
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Jun 17, 2026
May 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
1Gitlab
1Gitlab
Jun 17, 2026
May 23, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.
1Microsoft
1Edge Chromium
Jun 17, 2026
May 2, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.