CVE-2026-0295 PUBLISHED

GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

Assigner: palo_alto
Reserved: 03.11.2025 Published: 13.08.2026 Updated: 13.08.2026

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.

The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 4.1

Product Status

Vendor Palo Alto Networks
Product GlobalProtect App
Versions Default: unaffected
  • affected from 6.3.0 to 6.3.3-h14 (6.3.3-1121) (excl.)
  • affected from 6.2.0 to 6.2.8-h13 (6.2.8-1045) (excl.)
  • affected from 6.0.0 to 6.0.15 (excl.)
Vendor Palo Alto Networks
Product GlobalProtect App
Versions Default: unaffected
  • Version All is unaffected

Affected Configurations

No special configuration is required to be affected by this issue.

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Workarounds

No known workarounds or mitigations exist for this issue.

Credits

  • Alex Bourla and Graham Brereton finder

References

Problem Types

  • CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE

Impacts

  • CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions