Description
A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges.

This issue only affects Prisma® Browser on macOS.
Published: 2026-07-09
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privilege escalation flaw exists in Palo Alto Networks Prisma Browser on macOS that allows a locally authenticated administrator to elevate privileges to root. The weakness is classified under CWE‑269, meaning an attacker can bypass privilege limits, potentially affecting the confidentiality, integrity, or availability of the host. The impact is limited to machines where Prisma Browser is installed and requires an administrator with filesystem access.

Affected Systems

The affected product is Palo Alto Networks Prisma Browser running on macOS. Only installations of Prisma Browser on macOS are vulnerable; other vendors, platforms, or product versions are unaffected according to the vendor data.

Risk and Exploitability

The CVSS score is 2, reflecting a low overall severity, and the EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no known active exploitation is reported. The likely attack vector is local: it requires a user who is already authenticated as an administrator on the macOS system and able to access the local filesystem. Although the exploit potential is low, the ability to execute root‑level actions warrants remediation.

Generated by OpenCVE AI on July 29, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Prisma Browser to version 150.33.2.46 or later.
  • Reduce local administrator privileges on macOS for users who do not need elevated rights to operate Prisma Browser.
  • Apply strict file permissions to the Prisma Browser installation directory and related data to deny unauthorized modifications.

Generated by OpenCVE AI on July 29, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS.
Title Prisma Browser: Local Privilege Escalation on macOS
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Browser
Weaknesses CWE-269
CPEs cpe:2.3:a:palo_alto_networks:prisma_browser:*:*:macos:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Browser
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Browser
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-07-14T14:32:31.774Z

Reserved: 2025-11-03T20:44:34.621Z

Link: CVE-2026-0275

cve-icon Vulnrichment

Updated: 2026-07-14T14:32:28.067Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management