Incorrect Privilege Assignment in Palo Alto Networks GlobalProtect App on macOS
CVE-2025-0135
What is CVE-2025-0135?
A privilege assignment vulnerability in the Palo Alto Networks GlobalProtect App for macOS allows a locally authenticated non-administrative user to disable the application. This can lead to potential security risks for the network, as it permits users unauthorized control over the app's functionality. Other platforms, including Windows, Linux, iOS, Android, Chrome OS, and the GlobalProtect UWP app, remain unaffected. It's crucial for users to remain vigilant and implement necessary security measures to protect their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GlobalProtect App macOS 6.3.0 < 6.3.3
GlobalProtect App macOS 6.2.0 < 6.2.8
GlobalProtect App macOS 6.1.0
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved