Impact
The vulnerability resides in the Account Protection feature of Palo Alto Networks Prisma Browser and permits a local attacker to read sensitive data that should be protected. Because the flaw involves insecure handling of stored credentials (CWE‑522), the attacker could retrieve confidential login information or other protected values. This leads to a disclosure of sensitive information to a user with local access to the system.
Affected Systems
Palo Alto Networks Prisma Browser versions prior to 148.18.4.217 are affected. The issue is present in all releases that use the legacy Account Protection implementation, so any installation lacking the 148.18.4.217 update is vulnerable.
Risk and Exploitability
The CVSS score of 0.5 indicates a minimal severity under the current assessment, and no EPSS data is available, suggesting low known exploitation likelihood. The flaw can be exploited only by an attacker who already has local access to the device; there is no remote exploitation vector. The vulnerability is not listed in the CISA KEV catalog, further indicating that it has not yet been widely exploited in the wild.
OpenCVE Enrichment