CVE-2026-0237
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
Severity
High 7.3
CVSS 4.0
Exploited
Not listed
EPSS
0.002
4.5th percentile
Discovered by
Third party
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto
Description
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
Weakness: CWE-424
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Browser | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Prisma Browser
Credit
Cisors
Vendor remediation
VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 146.16.6.165 or later.