CWE-451

CWE-451 · 17 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-451, highest CVSS first.

  1. HIGH 7.4CVE-2026-94183

    Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI element…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.4CVE-2026-94181

    An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.4CVE-2026-102314

    UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.4CVE-2026-102305

    UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.4CVE-2026-95363

    UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.4CVE-2026-95337

    UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.4CVE-2026-95323

    UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 5.4CVE-2026-95321

    UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 5.4CVE-2026-95309

    UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 5.4CVE-2026-95307

    UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 5.4CVE-2026-95294

    UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 5.4CVE-2026-95291

    UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 5.4CVE-2026-95288

    UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  14. MEDIUM 5.4CVE-2026-95279

    UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  15. MEDIUM 4.8CVE-2026-95346

    UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium)

    AI risk analysis on Exploit-DB.ai →

  16. MEDIUM 4.8CVE-2026-95305

    UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  17. UNSCOREDCVE-2026-102312

    UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)

    AI risk analysis on Exploit-DB.ai →