Executive brief
A race condition vulnerability in Palo Alto Networks Prisma Browser allows a local user to bypass security policies. Prisma Browser is an enterprise-grade browser designed to enforce corporate data and access controls. An attacker with local access to the system could exploit this flaw to circumvent restrictions on sensitive data or unauthorized websites, potentially leading to data leakage or unauthorized access to internal resources.
Technical details
A race condition vulnerability (CWE-362) exists in Palo Alto Networks Prisma Browser due to improper synchronization during the execution of shared resources. A locally authenticated, non-administrative attacker can exploit this timing flaw to bypass configured access and data control policies. The vulnerability requires local access and has high attack complexity due to the nature of race conditions. Successful exploitation allows the attacker to access data or network resources that should be restricted by the browser's security engine. The issue is resolved in Prisma Browser version 146.16.6.165 and all subsequent versions.
Affected products
- Palo Alto Networks Prisma Browser versions before 146.16.6.165
Timeline
- 2026-05-13: disclosed: Initial publication of the advisory
- 2026-05-13: patched: Fixes released in version 146.16.6.165