Description
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Problem types
CWE-266: Incorrect Privilege Assignment
Product status
6.3.0 (custom) before 6.3.3
6.2.0 (custom) before 6.2.8
6.1.0 (custom)
6.0.0 (custom)
All (custom)
All (custom)
Timeline
| 2025-05-14: | Initial Publication |
Credits
Alex Bourla (alex.bourla@form3.tech)
Graham Brereton (graham.brereton@form3.tech)
References
security.paloaltonetworks.com/CVE-2025-0135