Impact
A race condition (CWE-754) in Prisma Browser allows a locally authenticated user without administrative privileges to circumvent configured access and data control policies, potentially exposing sensitive data or allowing unauthorized actions within the controlled environment. This flaw does not provide direct remote code execution but enables policy violations that could affect data confidentiality and integrity.
Affected Systems
The vulnerability affects Palo Alto Networks Prisma Browser on systems that run the software and have users with local, non-admin credentials. No specific version ranges are listed in the current entry; the documented fix is an upgrade to version 146.16.6.165 or later.
Risk and Exploitability
The CVSS base score is 5.8, indicating moderate severity, while the EPSS score is not available and the issue is not listed in CISA’s KEV catalog. Exploitation requires local presence and race-condition timing, making it a local attack vector that could enable a non-admin user to bypass control mechanisms. The lack of remote access requirements reduces broader exposure, but the risk remains significant for environments relying on Prisma Browser for enforcement of access policies.
OpenCVE Enrichment