CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
Description
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| GlobalProtect App | None on Linux None on Windows None on iOS None on Android None on Chrome OS | All on Linux All on Windows All on iOS All on Android All on Chrome OS |
| GlobalProtect App 6.3 | < 6.3.3-h14 (6.3.3-1121) on macOS | >= 6.3.3-h14 (6.3.3-1121) on macOS |
| GlobalProtect App 6.2 | < 6.2.8-h13 (6.2.8-1045) on macOS | >= 6.2.8-h13 (6.2.8-1045) on macOS |
| GlobalProtect App 6.0 | < 6.0.15 on macOS | >= 6.0.15 on macOS (ETA: 08/31) |
Required Configuration for Exposure
No special configuration is required to be affected by this issue.
Severity: MEDIUM, Suggested Urgency: MODERATE
CVSS-BT: 4.1 / CVSS-B: 7.2 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Weakness Type and Impact
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions
Solution
| Version | Minor Version | Suggested Solution |
|---|---|---|
| GlobalProtect App 6.3 on macOS |
6.3.0 through 6.3.3-h13 | Upgrade to 6.3.3-h14 (6.3.3-1121) or later. |
| GlobalProtect App 6.2 on macOS |
6.2.0 through 6.2.8-h12 | Upgrade to 6.2.8-h13 (6.2.8-1045) or later. |
| GlobalProtect App 6.0 on macOS | 6.0.0 through 6.0.14 | Upgrade to 6.0.15 or later. |
| GlobalProtect App on Linux | No action needed. | |
| GlobalProtect App on Windows | No action needed. | |
| GlobalProtect App on iOS | No action needed. | |
| GlobalProtect App on Android | No action needed. | |
| GlobalProtect App on Chrome OS | No action needed. |
Workarounds and Mitigations
No known workarounds or mitigations exist for this issue.
Acknowledgments
CPEs
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.2:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.1:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.0:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.8:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.7:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.6:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.4:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.3:*:*:*:*:macOS:*:*
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.2.2:*:*:*:*:macOS:*:*
CPE Applicability
- cpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:macOS:*:* is vulnerable from (including)6.3.3 and up to (excluding)6.3.3-h14
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:macOS:*:* is vulnerable from (including)6.2.8 and up to (excluding)6.2.8-h13
- ORcpe:2.3:a:palo_alto_networks:globalprotect_app:*:*:*:*:*:macOS:*:* is vulnerable from (including)6.0.0 and up to (excluding)6.0.15