CWE-451: User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
128 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-79011 — UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi
- CVE-2024-52277 — PDF Document Spoofing in DocuSeal
- CVE-2024-52276 — PDF Document Spoofing in DocuSign
- CVE-2024-52271 — PDF Document Spoofing in Documenso
- CVE-2024-52270 — PDF Document Spoofing in DropBox Sign(HelloSign)
- CVE-2024-52269 — AI Assistant PDF Document Spoofing in DocuSign
- CVE-2026-79108 — UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a
- CVE-2026-79176 — UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social e
- CVE-2026-32303 — Cryptomator: Tampered vault configuration allows MITM attack on Hub API
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2019-25718 — Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
- CVE-2026-53829 — OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
- CVE-2026-78974 — UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragi
- CVE-2026-79283 — UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements
- CVE-2026-79250 — UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address ba
- CVE-2026-79204 — UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI el
- CVE-2026-79180 — UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever
- CVE-2026-79173 — UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI ele
- CVE-2026-78912 — UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements v
- CVE-2025-9491 — Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
Recently published
- CVE-2026-87583 — UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spo
- CVE-2026-87624 — UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who ha
- CVE-2026-87597 — UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to sp
- CVE-2026-87653 — UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to sp
- CVE-2026-87635 — UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements
- CVE-2026-87484 — UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social eng
- CVE-2026-87458 — UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social eng
- CVE-2026-87496 — UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engi
- CVE-2026-87567 — UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging socia
- CVE-2026-87445 — UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements v
- CVE-2026-87649 — UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social en
- CVE-2026-87462 — UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engine
- CVE-2026-87559 — UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeri
- CVE-2026-87507 — UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social en
- CVE-2026-87501 — UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements
- CVE-2025-52652 — HCL MyXalytics is affected by multiple security vulnerabilities.
- CVE-2026-63020 — BIG-IP Configuration utility vulnerability
- CVE-2026-84356 — UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address ba
- CVE-2026-84330 — UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to sp
- CVE-2026-79108 — UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a
More specific weaknesses
- CWE-1007 — Insufficient Visual Distinction of Homoglyphs Presented to User