CVE-2026-0237: Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0237?
CVE-2026-0237 has been classified with a high severity rating due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2026-0237?
To fix CVE-2026-0237, update the Palo Alto Networks Prisma Browser to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-0237?
CVE-2026-0237 specifically affects users of Palo Alto Networks Prisma Browser on macOS, particularly those with non-admin user accounts.
What kind of attack can exploit CVE-2026-0237?
CVE-2026-0237 can be exploited by a locally authenticated non-admin user to bypass security restrictions and access restricted functionalities.
When was CVE-2026-0237 reported?
CVE-2026-0237 was reported in 2026, highlighting the need for timely updates to the affected software.