CVE-2026-0237
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
13/05/2026
Last modified:
13/05/2026
Description
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.



