Back

MEDIUM

GlobalProtect App: Non Admin User Can Disable the GlobalProtect App

Published Jul 9, 2025

Description

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so.

The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Affected products

Remediation

Vendor solution

Version Minor Version Suggested Solution

GlobalProtect App 6.3 on macOS

6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later.

GlobalProtect App 6.2 on macOS

6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.1 on macOSUpgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later.GlobalProtect App 6.0 on macOSUpgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later.GlobalProtect App on Android, iOS, Linux, Windows  No action needed.GlobalProtect UWP App No action needed.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Jul 9, 2025
Updated Jul 30, 2025
Reserved Dec 20, 2024
CISA Vulnrichment
Updated Jul 10, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner palo_alto
Published Jul 9, 2025
Updated Jul 30, 2025
Exploited since n/a
EUVD-2025-20880