An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials.
The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.
The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic.
The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed.
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content.
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. A privacy issue was addressed by removing sensitive data.
802.1X. An authentication issue was addressed with improved state management.
802.1X. An authentication issue was addressed with improved state management.
802.1X. An authentication issue was addressed with improved state management.
Accessibility. This issue was addressed through improved state management.
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315161
Accessibility. This issue was addressed through improved state management.
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected Safari crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313691