Executive brief
Palo Alto Networks Prisma Browser is an enterprise-grade web browser designed for secure corporate access. A security flaw in the macOS version of this browser allows a standard user on a computer to bypass security restrictions and send unauthorized commands to the browser's internal systems. This could allow an attacker with local access to the machine to circumvent corporate security controls and potentially access sensitive data or perform unauthorized actions within the browser.
Technical details
An improper protection of alternate path vulnerability (CWE-424) exists in Palo Alto Networks Prisma Browser for macOS. The flaw resides in the failure to properly restrict access to an internal automation bridge, which serves as a communication channel for browser operations. A locally authenticated non-admin user can exploit this exposed channel to send unauthorized commands directly to the browser. This allows the attacker to bypass established security controls and potentially achieve full compromise of the browser session. The vulnerability is addressed in Prisma Browser version 146.16.6.165 and later.
Affected products
- Palo Alto Networks Prisma Browser < 146.16.6.165
Timeline
- 2026-05-13: disclosed: Initial publication of the advisory
- 2026-05-13: patched: Fix released in version 146.16.6.165