Palo Alto Networks: numerous security holes in Prisma Browser closed
Summary
In August 2026 Palo Alto Networks closed numerous holes, most of them in the Chromium-based enterprise browser Prisma Browser. There, memory bugs could lead to code execution; version 150.49.8.187 was fixed. Further holes affected the GlobalProtect VPN client on Android, macOS and Windows, including a privilege escalation (CVE-2026-0299).
Ideas
- Chromium-based enterprise browsers inherit its memory bugs.
- CVSS 4.0 distinguishes the base score from a score that includes the current threat situation.
- The absence of attacks lowers the urgency, not the severity.
- VPN clients can grant local admin rights.
Insights
- Additional security products bring their own attack surface.
- Threat-based scores help with prioritisation but do not replace prompt patching.
Facts
- For Prisma Browser, CVSS-B 9.2 and CVSS-BT 7.2 applied.
- No attacks were known at the time of the report.
References
Critique
- The report lists products without classifying the individual holes technically.
Recommendations
- Include enterprise browsers and VPN clients in regular patch management.
- Use CVSS-BT for prioritisation, but also plan prompt updates for holes that are not being exploited.
Links to the original source and the Web Archive open in a new tab.