Executive brief
A security flaw in the Prisma Access Agent for Android and Chrome OS could allow an attacker to intercept encrypted VPN traffic. By positioning themselves on the same local network as a user, an attacker could capture sensitive device information and monitor communications. This issue does not affect the agent on Windows, macOS, Linux, or iOS.
Technical details
An improper certificate validation vulnerability (CWE-295) exists in the Palo Alto Networks Prisma Access Agent for Android and Chrome OS. The application fails to properly verify the identity of the server, allowing an attacker to present a certificate for any domain issued by a trusted Certificate Authority to successfully intercept traffic. An attacker positioned on the same local network (adjacent) can perform a man-in-the-middle (MitM) attack to capture sensitive device information and intercept VPN communications. The vulnerability is fixed in Prisma Access Agent version 26.2.1. Versions for macOS, Windows, Linux, and iOS are not affected.
Affected products
- Palo Alto Networks Prisma Access Agent < 26.2.1 on Android and Chrome OS
Timeline
- 2026-05-13: disclosed: Initial publication by Palo Alto Networks
- 2026-05-13: patched: Fixed in version 26.2.1