Back

HIGH

Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass

Published May 13, 2026

Description

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

Affected products

Remediation

Vendor solution

VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 146.16.6.165 or later.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published May 13, 2026
Updated May 14, 2026
Reserved Nov 3, 2025
CISA Vulnrichment
Updated May 13, 2026
NVD
Status Analyzed
Modified Jul 14, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner palo_alto
Published May 13, 2026
Updated May 14, 2026
Exploited since n/a
EUVD-2026-30062