Junglewise Threat Intelligence

CVE-2026-0275: Palo Alto Networks Prisma Browser privilege escalation in macOS

CVE-2026-0275 · Severity: info · CVSS 7.2 · Published 2026-07-09

Technologies: Palo Alto Networks Prisma Browser. Vendors: Palo Alto Networks.

Executive brief

A security vulnerability in Palo Alto Networks Prisma Browser for macOS could allow a local administrator to gain full root-level control over the device. Prisma Browser is an enterprise-grade web browser designed for secure corporate access. If exploited, an attacker who already has administrative access to the computer could bypass standard security boundaries to perform any action on the system, potentially compromising sensitive data or system integrity.

Technical details

An improper privilege management vulnerability (CWE-269) exists in Palo Alto Networks Prisma Browser for macOS. The flaw allows a locally authenticated user with administrative privileges and access to the macOS local filesystem to escalate their permissions to root. This enables the attacker to perform unauthorized actions with the highest level of system authority. The issue is specific to the macOS platform and has been addressed in Prisma Browser version 150.33.2.46.

Affected products

  • Palo Alto Networks Prisma Browser 150.33.2.0 to 150.33.2.45

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched
  • 2026-07-09: advisory

References

Related threats