Executive brief
A security vulnerability exists in the Palo Alto Networks Prisma Browser for macOS, a specialized web browser designed for enterprise security. An attacker with existing access to a computer could bypass security controls to send unauthorized commands to the browser. This could allow them to interfere with browser operations or access sensitive information managed by the application.
Technical details
A code injection vulnerability (CWE-94) exists in Palo Alto Networks Prisma Browser for macOS due to improper access restrictions on its AppleScript interface. A locally authenticated, non-privileged user can exploit an exposed Apple Event handler to execute unauthorized commands within the context of the browser. This allows for the bypass of security controls and potential manipulation of browser data or functionality. The vulnerability is addressed in Prisma Browser version 146.16.6.165 and later.
Affected products
- Palo Alto Networks Prisma Browser versions before 146.16.6.165 on macOS
Timeline
- 2026-05-13: advisory: Initial publication by Palo Alto Networks
- 2026-05-13: disclosed
- 2026-07-13: other: NVD initial analysis completed