CVE-2026-0236

Prisma Browser: Code Injection Enables Security Controls Bypass

Severity
High 7.3
CVSS 4.0
Exploited
Not listed
EPSS
0.002
5.4th percentile
Discovered by
Third party
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto

Description

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.

Weakness: CWE-94

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Browser SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Prisma Browser

Credit

Cisors

Vendor remediation

VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 146.16.6.165 or later.