ON
← Back to feed
Palo Alto Networks: Many security flaws in Prisma browser closed
Germany💻 Technology11 days ago

Palo Alto Networks: Many security flaws in Prisma browser closed

Palo Alto Networks hat mehrere Sicherheitslücken in seinen Produkten wie Prisma Browser, GlobalProtect App und PAN-OS identifiziert und behoben. Die Schwachstellen ermöglichen potenziellen Angreifern, Schadsoftware auf Systeme zu bringen oder Adminrechte zu gewinnen. Die Sicherheitsupdates wurden veröffentlicht, und zwar unter Verwendung von CVE-Identifiern, die auf der Palo Alto Networks Security-Website zu finden sind. Obwohl die Schwachstellen als 'kritisch' eingestuft werden, gibt es derzeit keine Hinweise auf aktive Angriffe. Die Updates sind für verschiedene Plattformen verfügbar, einschließlich Android, macOS und Windows.

Palo Alto Networks has addressed multiple security vulnerabilities in its Prisma Browser, according to reports from German technology news outlet heise online. The company confirmed that several critical flaws have been patched, affecting its software suite including the GlobalProtect App, PAN-OS, and Prisma Browser. These vulnerabilities could allow attackers to exploit memory corruption issues, potentially leading to system compromise. As of now, there are no indications that attackers have exploited these weaknesses. The company’s website lists all the recently closed security issues, with a focus on the Prisma Browser, which is based on Chromium. Developers have resolved numerous vulnerabilities within this browser, particularly those that could enable remote code execution through memory errors. According to the report, version 150.49.8.187 of the Prisma Browser has been updated to address these concerns. The patching effort was carried out in response to identified risks, ensuring that users benefit from enhanced protection against potential cyber threats. Palo Alto Networks uses two severity ratings for each vulnerability, based on the CVSS Score 4.0 framework. For the Prisma Browser, the base score (CVSS-B) is rated at 9.2, classified as “critical,” while the threat-based score (CVSS-BT) is 7.2, labeled as “high.” The base score represents the inherent risk level of the flaw, whereas the threat-based score incorporates current threat intelligence. Despite the high severity rating, there are currently no known active attacks exploiting these vulnerabilities, so administrators are advised to apply the patches at their discretion rather than urgently. Among the remaining unresolved issues, many pertain to the GlobalProtect App, which facilitates secure virtual private network (VPN) connections in corporate environments. This app is available for Android, macOS, and Windows platforms, making it widely used across enterprise networks. One specific vulnerability, CVE-2026-0299, is marked as “high” under the base score and “medium” under the threat-based assessment. If successfully exploited, this flaw could grant attackers administrative privileges, posing a significant risk to network security. The affected systems include both internal corporate infrastructure and external user devices connected to enterprise networks. Given the widespread deployment of Palo Alto Networks' products, the potential impact of these vulnerabilities extends beyond individual users to organizations relying on the company's security solutions. While the immediate threat appears low due to the absence of ongoing exploitation attempts, the presence of critical flaws underscores the importance of timely updates and proactive cybersecurity measures. Security experts recommend that businesses review their update policies and ensure that all relevant software components are running the latest versions. This includes not only the Prisma Browser but also the GlobalProtect App and other related tools. Organizations should conduct regular audits to identify and mitigate potential attack vectors, especially those involving outdated or unpatched software. As Palo Alto Networks continues to monitor the situation, further advisories or updates may be issued to address emerging threats or refine existing mitigations.

Go to the primary sources (2)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 40Objective 4511 days ago
Palo Alto Networks: Many security flaws in Prisma browser closed

Palo Alto Networks hat mehrere Sicherheitslücken in seinen Produkten wie Prisma Browser, GlobalProtect App und PAN-OS identifiziert und behoben. Die Schwachstellen ermöglichen potenziellen Angreifern, Schadsoftware auf Systeme zu bringen oder Adminrechte zu gewinnen. Die Sicherheitsupdates wurden veröffentlicht, und zwar unter Verwendung von CVE-Identifiern, die auf der Palo Alto Networks Security-Website zu finden sind. Obwohl die Schwachstellen als 'kritisch' eingestuft werden, gibt es derzeit keine Hinweise auf aktive Angriffe. Die Updates sind für verschiedene Plattformen verfügbar, einschließlich Android, macOS und Windows.

Bias read (Center): Die Berichterstattung konzentriert sich rein auf technische Aspekte der Sicherheitslücken und deren Behandlung. Es wird keine politische Haltung oder parteiengesellschaftliche Bewertung geäußert. Die Quellen sind objektiv und berichten nur Fakten ohne emotionale oder ideologische Einflussnahme.

Why factuality (40): The article incorrectly reports multiple vulnerabilities in 'Prisma Browser' and references CVE-2026-0299, which does not exist in the primary source document. It also falsely states that the CVSS-B score for Prisma is 9.2 'critical', whereas the actual CVSS-B score for the reported vulnerability (C

Why objectivity (45): The article uses emotionally charged terms like 'angreifbar' (attackable) and 'vollständig kompromittiert' (fully compromised), suggesting immediate danger. It frames the situation as more severe than indicated by the primary source, which states no exploitation has been observed. The tone leans tow

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories