Vulnerability Description
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Prisma Browser | < 146.16.6.165 |
| Apple | Macos | - |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2026-0237Vendor Advisory
FAQ
What is CVE-2026-0237?
CVE-2026-0237 is a vulnerability with a CVSS score of 7.8 (HIGH). An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenti...
How severe is CVE-2026-0237?
CVE-2026-0237 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0237?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Prisma Browser, Apple Macos.