Threadlinqs IntelligenceStart free

Weakness · ClassCWE-451

CWE-451: User Interface (UI) Misrepresentation of Critical Information

Class

As of 2026-10-05, CWE-451 (User Interface (UI) Misrepresentation of Critical Information) underlies 3 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 109 tracked threats.

CVEs
3Mapped to CWE-451
CISA KEV
0None listed yet
Critical
0CVSS v3 critical CVEs
Threats
109Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-451?

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

If an attacker can cause the UI to display erroneous data, or to otherwise convince the user to display information that appears to come from a trusted source, then the attacker could trick the user into performing the wrong action. This is often a component in phishing attacks, but other kinds of problems exist. For example, if the UI is used to monitor the security state of a system or network, then omitting or obscuring an important indicator could prevent the user from detecting and reacting to a security-critical event. UI misrepresentation can take many forms: Incorrect indicator: incorrect information is displayed, which prevents the user from understanding the true state of the product or the environment the product is monitoring, especially of potentially-dangerous conditions or operations. This can be broken down into several different subtypes. Overlay: an area of the display is intended to give critical information, but another process can modify the display by overlaying another element on top of it. The user is not interacting with the expected portion of the user interface. This is the problem that enables clickjacking attacks, although many other types of attacks exist that involve overlay. Icon manipulation: the wrong icon, or the wrong color indicator, can be influenced (such as making a dangerous .EXE executable look like a harmless .GIF) Timing: the product is performing a state transition or context switch that is presented to the user with an indicator, but a race condition can cause the wrong indicator to be used before the product has fully switched context. The race window could be extended indefinitely if the attacker can trigger an error. Visual truncation: important information could be truncated from the display, such as a long filename with a dangerous extension that is not displayed in the GUI because the malicious portion is truncated. The use of excessive whitespace can also cause truncation, or place the potentially-dangerous indicator outside of the user's field of view (e.g. "filename.txt .exe"). A different type of truncation can occur when a portion of the information is removed due to reasons other than length, such as the accidental insertion of an end-of-input marker in the middle of an input, such as a NUL byte in a C-style string. Visual distinction: visual information might be presented in a way that makes it difficult for the user to quickly and correctly distinguish between critical and unimportant segments of…

CWE-451 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Operating_System: Not OS-Specific; Technology: Not Technology-Specific.

Source: MITRE CWE (CWE-451 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Non-Repudiation, Access Control — Hide Activities, Bypass Protection Mechanism

Source: MITRE CWE, common consequences.

How CWE-451 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-451, published between 2025-08-26 and 2026-09-29. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 1 medium. The highest EPSS score in the set is 63.1% (CVE-2025-9491), the modelled probability of exploitation in the next 30 days. 109 tracked threats reference CWE-451 directly or through a CVE it covers; the most recent is “Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)” (2026-09-30). Affected products concentrate in Google (2), Microsoft (2), Apple (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-451, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

109 tracked threats cite CWE-451; the 25 most recent are listed.

Mitigations

  • Implementation / Input Validation: Perform data validation (e.g. syntax, length, etc.) before interpreting the data.
  • Architecture and Design / Output Encoding: Create a strategy for presenting information, and plan for how to display unusual characters.

Source: MITRE CWE, potential mitigations.