CVE-2025-0135
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
14/05/2025
Last modified:
27/06/2025
Description
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app.<br />
<br />
The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Impact
Base Score 4.0
5.20
Severity 4.0
MEDIUM
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* | 6.0.0 (including) | 6.2.8 (excluding) |
| cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* | 6.3.0 (including) | 6.3.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



