CVE-2026-0236: Prisma Browser: Code Injection Enables Security Controls Bypass
A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0236?
CVE-2026-0236 is classified as a high severity vulnerability.
How do I fix CVE-2026-0236?
To fix CVE-2026-0236, update the Palo Alto Networks Prisma Browser to the latest version that addresses the vulnerability.
Who is affected by CVE-2026-0236?
CVE-2026-0236 affects locally authenticated non-admin users on macOS using Palo Alto Networks Prisma Browser.
What type of vulnerability is CVE-2026-0236?
CVE-2026-0236 is a code injection vulnerability allowing security controls bypass.
What does the CVE-2026-0236 vulnerability allow an attacker to do?
CVE-2026-0236 allows a locally authenticated non-admin user to exploit the Apple Event handler and bypass security controls.