CVE-2025-0135: GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ app on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so.
The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Other sources
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app.
The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
— NVD
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0135?
CVE-2025-0135 is classified as a privilege escalation vulnerability that allows a non-administrative user to disable the Palo Alto Networks GlobalProtect App on macOS devices.
How do I fix CVE-2025-0135?
To mitigate CVE-2025-0135, ensure that you upgrade to the latest version of the Palo Alto Networks GlobalProtect App that addresses this vulnerability.
Who is affected by CVE-2025-0135?
CVE-2025-0135 specifically affects users of the Palo Alto Networks GlobalProtect App on macOS devices.
Can CVE-2025-0135 be exploited remotely?
No, CVE-2025-0135 can only be exploited by a locally authenticated user on the macOS system.
What versions of GlobalProtect are vulnerable to CVE-2025-0135?
Versions of the Palo Alto Networks GlobalProtect App prior to the fix are vulnerable, specifically 6.3.3 and earlier.