NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-0237
Summary

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

Publication Date May 14, 2026, 3:16 a.m.
Registration Date May 15, 2026, 4:21 a.m.
Last Update May 14, 2026, 3:17 a.m.
Related information, measures and tools
Common Vulnerabilities List