What is CWE-451?
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
If an attacker can cause the UI to display erroneous data, or to otherwise convince the user to display information that appears to come from a trusted source, then the attacker could trick the user into performing the wrong action. This is often a component in phishing attacks, but other kinds of problems exist. For example, if the UI is used to monitor the security state of a system or network, then omitting or obscuring an important indicator could prevent the user from detecting and reacting to a security-critical event. UI misrepresentation can take many forms: Incorrect indicator: incorrect information is displayed, which prevents the user from understanding the true state of the product or the environment the product is monitoring, especially of potentially-dangerous conditions or operations. This can be broken down into several different subtypes. Overlay: an area of the display is intended to give critical information, but another process can modify the display by overlaying another element on top of it. The user is not interacting with the expected portion of the user interface. This is the problem that enables clickjacking attacks, although many other types of attacks exist that involve overlay. Icon manipulation: the wrong icon, or the wrong color indicator, can be influenced (such as making a dangerous .EXE executable look like a harmless .GIF) Timing: the product is performing a state transition or context switch that is presented to the user with an indicator, but a race condition can cause the wrong indicator to be used before the product has fully switched context. The race window could be extended indefinitely if the attacker can trigger an error. Visual truncation: important information could be truncated from the display, such as a long filename with a dangerous extension that is not displayed in the GUI because the malicious portion is truncated. The use of excessive whitespace can also cause truncation, or place the potentially-dangerous indicator outside of the user's field of view (e.g. "filename.txt .exe"). A different type of truncation can occur when a portion of the information is removed due to reasons other than length, such as the accidental insertion of an end-of-input marker in the middle of an input, such as a NUL byte in a C-style string. Visual distinction: visual information might be presented in a way that makes it difficult for the user to quickly and correctly distinguish between critical and unimportant segments of…
CWE-451 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Operating_System: Not OS-Specific; Technology: Not Technology-Specific.
Source: MITRE CWE (CWE-451 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Non-Repudiation, Access Control — Hide Activities, Bypass Protection Mechanism
Source: MITRE CWE, common consequences.
How CWE-451 is exploited in the wild
Threadlinqs maps 3 CVEs to CWE-451, published between 2025-08-26 and 2026-09-29. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 1 medium. The highest EPSS score in the set is 63.1% (CVE-2025-9491), the modelled probability of exploitation in the next 30 days. 109 tracked threats reference CWE-451 directly or through a CVE it covers; the most recent is “Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)” (2026-09-30). Affected products concentrate in Google (2), Microsoft (2), Apple (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 3 CVEs mapped to CWE-451, CISA KEV first, then by CVSS score.
- CVE-2025-9491 — CVSS 7 high · EPSS 63.1% · published 2025-08-26
- CVE-2026-9110 — CVSS 4.2 medium · EPSS 0.0% · published 2026-05-20
- CVE-2026-102312 — published 2026-09-29
Affected vendors
Threat activity
109 tracked threats cite CWE-451; the 25 most recent are listed.
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google CredentialsMEDIUM
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google CredentialsMEDIUM
- Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote AccessHIGH
- Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME SpoofingHIGH
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake Video-Conference Lures Bypass MFA and Security Awareness TrainingMEDIUM
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock BypassHIGH
- 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages)MEDIUM
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial AccessMEDIUM
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack ChainsHIGH
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)HIGH
- CSS Bomb Attacks: CSS-Based Trust-Boundary Bypass Leaks Webmail Passwords and Tokens (Outlook, Gmail, Yahoo, AOL, Fastmail, Proton Mail)HIGH
- CSS Bomb: JavaScript-Free CSS Keylogging and Token-Theft Attacks Against Gmail, Outlook, Yahoo Mail, AOL Mail, Fastmail, and ProtonMailHIGH
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for ExtortionHIGH
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal SectorHIGH
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" EmergesHIGH
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case (Shehabi v Kingdom of Bahrain)MEDIUM
- InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)HIGH
- ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation AttemptsMEDIUM
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.aiHIGH
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain TheftHIGH
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance PlatformHIGH
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational InstitutionsHIGH
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin)MEDIUM
- Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential TheftMEDIUM
Mitigations
- Implementation / Input Validation: Perform data validation (e.g. syntax, length, etc.) before interpreting the data.
- Architecture and Design / Output Encoding: Create a strategy for presenting information, and plan for how to display unusual characters.
Source: MITRE CWE, potential mitigations.