CVE-2026-0237
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
Severity
High 7.3
CVSS 4.0
Exploited
Not listed
EPSS
0.002
4.6th percentile
Discovered by
Third party
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto
Description
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
Weakness: CWE-424
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Browser | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Prisma Browser
Credit
Cisors
Vendor remediation
VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 146.16.6.165 or later.