Impact
The vulnerability in Palo Alto Networks Prisma Browser’s Account Protection feature allows a user to bypass the intended security controls, potentially granting unauthorized account access. This flaw falls under CWE‑522, indicating insufficient protection of sensitive information. Because the bypass can be achieved without triggering additional authentication or authorization checks, an attacker may gain privileged access to the browser session or underlying system.
Affected Systems
Affected are installations of Prisma Browser with versions earlier than 150.49.4.125. All users running the default configuration on these versions are susceptible until they apply the vendor‑supplied upgrade.
Risk and Exploitability
The CVSS score of 0.5 indicates a low severity risk for individual infections, and the EPSS score is not available; KEV does not list this vulnerability. Nonetheless, the flaw requires an attacker to be in a position to interact with the browser and leverage the bypass, making it a local or user‑initiated attack vector. Given the low scoring metrics, the likelihood of widespread exploitation is small, but it remains a potential internal threat especially in environments where account protection is relied upon for secure access.
OpenCVE Enrichment