Impact
A race condition in the Palo Alto Networks GlobalProtect client on macOS allows a locally authenticated low‑privileged attacker to elevate privileges to root. The flaw, identified as a concurrency error (CWE‑362), grants the attacker full system control, enabling installation of malware, exfiltration of data, or tampering with critical system files. The impact is a complete compromise of the local machine, with potential cascading effects on network security if the device is part of a corporate environment.
Affected Systems
Affected are all macOS versions of the GlobalProtect App from 6.0.0 through 6.0.14, 6.2.0 through 6.2.8‑h12, and 6.3.0 through 6.3.3‑h13. The patching guidance specifies upgrading to 6.0.15 or later, 6.2.8‑h13 (6.2.8‑1045) or later, and 6.3.3‑h14 (6.3.3‑1121) or later. Linux, Windows, iOS, Android, Chrome OS, and other platforms are not affected.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, authenticated access, typically a user with restricted privileges on a macOS device. Because a race condition can be difficult to trigger reliably and no workaround exists, the risk is primarily higher for otherwise unattended devices where a malicious application or script can initiate the race.
OpenCVE Enrichment