Palo Alto Networks has addressed multiple security vulnerabilities in its Prisma Browser, according to reports from German technology news outlet heise online. The company confirmed that several critical flaws have been patched, affecting its software suite including the GlobalProtect App, PAN-OS, and Prisma Browser. These vulnerabilities could allow attackers to exploit memory corruption issues, potentially leading to system compromise. As of now, there are no indications that attackers have exploited these weaknesses. The company’s website lists all the recently closed security issues, with a focus on the Prisma Browser, which is based on Chromium. Developers have resolved numerous vulnerabilities within this browser, particularly those that could enable remote code execution through memory errors. According to the report, version 150.49.8.187 of the Prisma Browser has been updated to address these concerns. The patching effort was carried out in response to identified risks, ensuring that users benefit from enhanced protection against potential cyber threats. Palo Alto Networks uses two severity ratings for each vulnerability, based on the CVSS Score 4.0 framework. For the Prisma Browser, the base score (CVSS-B) is rated at 9.2, classified as “critical,” while the threat-based score (CVSS-BT) is 7.2, labeled as “high.” The base score represents the inherent risk level of the flaw, whereas the threat-based score incorporates current threat intelligence. Despite the high severity rating, there are currently no known active attacks exploiting these vulnerabilities, so administrators are advised to apply the patches at their discretion rather than urgently. Among the remaining unresolved issues, many pertain to the GlobalProtect App, which facilitates secure virtual private network (VPN) connections in corporate environments. This app is available for Android, macOS, and Windows platforms, making it widely used across enterprise networks. One specific vulnerability, CVE-2026-0299, is marked as “high” under the base score and “medium” under the threat-based assessment. If successfully exploited, this flaw could grant attackers administrative privileges, posing a significant risk to network security. The affected systems include both internal corporate infrastructure and external user devices connected to enterprise networks. Given the widespread deployment of Palo Alto Networks' products, the potential impact of these vulnerabilities extends beyond individual users to organizations relying on the company's security solutions. While the immediate threat appears low due to the absence of ongoing exploitation attempts, the presence of critical flaws underscores the importance of timely updates and proactive cybersecurity measures. Security experts recommend that businesses review their update policies and ensure that all relevant software components are running the latest versions. This includes not only the Prisma Browser but also the GlobalProtect App and other related tools. Organizations should conduct regular audits to identify and mitigate potential attack vectors, especially those involving outdated or unpatched software. As Palo Alto Networks continues to monitor the situation, further advisories or updates may be issued to address emerging threats or refine existing mitigations.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter