PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)
Exploit Maturity
UNREPORTED
Response Effort
MODERATE
Recovery
AUTOMATIC
Value Density
DIFFUSE
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Automatable
NO
User Interaction
NONE
Product Confidentiality
HIGH
Product Integrity
HIGH
Product Availability
HIGH
Privileges Required
NONE
Subsequent Confidentiality
HIGH
Subsequent Integrity
HIGH
Subsequent Availability
HIGH
Description
Palo Alto Networks incorporated the following Chromium security fixes into our products:
- https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
- https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html
- https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html
| CVE | Summary |
|---|---|
| CVE-2026-8509 | Heap buffer overflow in WebML |
| CVE-2026-8510 | Integer overflow in Skia |
| CVE-2026-8511 | Use after free in UI |
| CVE-2026-8512 | Use after free in FileSystem |
| CVE-2026-8513 | Use after free in Input |
| CVE-2026-8514 | Use after free in Aura |
| CVE-2026-8515 | Use after free in HID |
| CVE-2026-8516 | Insufficient validation of untrusted input in DataTransfer |
| CVE-2026-8517 | Object lifecycle issue in WebShare |
| CVE-2026-8518 | Use after free in Blink |
| CVE-2026-8519 | Integer overflow in ANGLE |
| CVE-2026-8520 | Race in Payments |
| CVE-2026-8521 | Use after free in Tab Groups |
| CVE-2026-8522 | Use after free in Downloads |
| CVE-2026-8523 | Use after free in Mojo |
| CVE-2026-8524 | Out of bounds write in WebAudio |
| CVE-2026-8525 | Heap buffer overflow in ANGLE |
| CVE-2026-8526 | Out of bounds write in WebRTC |
| CVE-2026-8527 | Insufficient validation of untrusted input in Downloads |
| CVE-2026-8528 | Insufficient validation of untrusted input in SiteIsolation |
| CVE-2026-8529 | Heap buffer overflow in Codecs |
| CVE-2026-8530 | Use after free in Network |
| CVE-2026-8531 | Heap buffer overflow in WebML |
| CVE-2026-8532 | Integer overflow in XML |
| CVE-2026-8533 | Use after free in Accessibility |
| CVE-2026-8534 | Integer overflow in GPU |
| CVE-2026-8535 | Out of bounds read in Media |
| CVE-2026-8536 | Insufficient validation of untrusted input in ReadingMode |
| CVE-2026-8537 | Insufficient policy enforcement in ViewTransitions |
| CVE-2026-8538 | Insufficient validation of untrusted input in GPU |
| CVE-2026-8539 | Script injection in SanitizerAPI |
| CVE-2026-8540 | Type Confusion in V8 |
| CVE-2026-8541 | Out of bounds read in UI |
| CVE-2026-8542 | Use after free in Core |
| CVE-2026-8543 | Out of bounds read in FileSystem |
| CVE-2026-8544 | Use after free in Media |
| CVE-2026-8545 | Object corruption in Compositing |
| CVE-2026-8546 | Out of bounds read in GPU |
| CVE-2026-8547 | Insufficient policy enforcement in Passwords |
| CVE-2026-8548 | Out of bounds write in Media |
| CVE-2026-8549 | Use after free in Media |
| CVE-2026-8550 | Use after free in Google Lens |
| CVE-2026-8551 | Use after free in Downloads |
| CVE-2026-8552 | Heap buffer overflow in GPU |
| CVE-2026-8553 | Use after free in GPU |
| CVE-2026-8554 | Type Confusion in ANGLE |
| CVE-2026-8555 | Use after free in GTK |
| CVE-2026-8556 | Inappropriate implementation in ANGLE |
| CVE-2026-8557 | Use after free in Accessibility |
| CVE-2026-8558 | Out of bounds write in Fonts |
| CVE-2026-8559 | Integer overflow in Internationalization |
| CVE-2026-8560 | Heap buffer overflow in SwiftShader |
| CVE-2026-8561 | Incorrect security UI in Fullscreen |
| CVE-2026-8562 | Side-channel information leakage in Navigation |
| CVE-2026-8563 | Insufficient policy enforcement in IFrame Sandbox |
| CVE-2026-8564 | Incorrect security UI in Downloads |
| CVE-2026-8565 | Inappropriate implementation in Downloads |
| CVE-2026-8566 | Insufficient policy enforcement in Payments |
| CVE-2026-8567 | Integer overflow in ANGLE |
| CVE-2026-8568 | Insufficient policy enforcement in AI |
| CVE-2026-8569 | Out of bounds write in Codecs |
| CVE-2026-8570 | Type Confusion in V8 |
| CVE-2026-8571 | Insufficient policy enforcement in GPU |
| CVE-2026-8572 | Insufficient policy enforcement in Network |
| CVE-2026-8573 | Integer overflow in Codecs |
| CVE-2026-8574 | Use after free in Core |
| CVE-2026-8575 | Use after free in UI |
| CVE-2026-8576 | Inappropriate implementation in CORS |
| CVE-2026-8577 | Integer overflow in Fonts |
| CVE-2026-8578 | Out of bounds read in GPU |
| CVE-2026-8579 | Insufficient validation of untrusted input in Skia |
| CVE-2026-8580 | Use after free in Mojo |
| CVE-2026-8581 | Use after free in GPU |
| CVE-2026-8582 | Object lifecycle issue in Dawn |
| CVE-2026-8583 | Insufficient policy enforcement in WebXR |
| CVE-2026-8584 | Inappropriate implementation in Views |
| CVE-2026-8585 | Inappropriate implementation in Media |
| CVE-2026-8586 | Inappropriate implementation in Chromoting |
| CVE-2026-8587 | Use after free in Extensions |
| CVE-2026-9110 | Inappropriate implementation in UI |
| CVE-2026-9111 | Use after free in WebRTC |
| CVE-2026-9112 | Use after free in GPU |
| CVE-2026-9113 | Out of bounds read in GPU |
| CVE-2026-9114 | Use after free in QUIC |
| CVE-2026-9115 | Insufficient policy enforcement in Service Worker |
| CVE-2026-9116 | Insufficient policy enforcement in ServiceWorker |
| CVE-2026-9117 | Type Confusion in GFX |
| CVE-2026-9118 | Use after free in XR |
| CVE-2026-9120 | Use after free in WebRTC |
| CVE-2026-9121 | Out of bounds read in GPU |
| CVE-2026-9123 | Heap buffer overflow in Chromecast |
| CVE-2026-9124 | Insufficient validation of untrusted input in Input |
| CVE-2026-9126 | Use after free in DOM |
| CVE-2026-9872 | Out of bounds write in GPU |
| CVE-2026-9873 | Use after free in Network |
| CVE-2026-9874 | Use after free in Dawn |
| CVE-2026-9875 | Out of bounds read in WebGL |
| CVE-2026-9876 | Use after free in WebGL |
| CVE-2026-9877 | Use after free in ANGLE |
| CVE-2026-9878 | Use after free in ANGLE |
| CVE-2026-9879 | Out of bounds write in ANGLE |
| CVE-2026-9880 | Insufficient validation of untrusted input in WebGL |
| CVE-2026-9881 | Use after free in Bluetooth |
| CVE-2026-9882 | Integer overflow in ANGLE |
| CVE-2026-9883 | Use after free in Base |
| CVE-2026-9884 | Use after free in Browser |
| CVE-2026-9885 | Insufficient validation of untrusted input in UI |
| CVE-2026-9886 | Use after free in Base |
| CVE-2026-9887 | Use after free in Proxy |
| CVE-2026-9888 | Use after free in WebView |
| CVE-2026-9889 | Out of bounds read and write in Dawn |
| CVE-2026-9890 | Use after free in XR |
| CVE-2026-9891 | Use after free in Extensions |
| CVE-2026-9892 | Inappropriate implementation in Skia |
| CVE-2026-9893 | Use after free in Skia |
| CVE-2026-9894 | Use after free in GPU |
| CVE-2026-9895 | Out of bounds read in GPU |
| CVE-2026-9896 | Out of bounds write in V8 |
| CVE-2026-9897 | Use after free in DOM |
| CVE-2026-9898 | Insufficient validation of untrusted input in GPU |
| CVE-2026-9899 | Use after free in ANGLE |
| CVE-2026-9900 | Out of bounds write in ANGLE |
| CVE-2026-9901 | Use after free in ANGLE |
| CVE-2026-9902 | Use after free in Accessibility |
| CVE-2026-9903 | Insufficient validation of untrusted input in Site Isolation |
| CVE-2026-9904 | Use after free in ANGLE |
| CVE-2026-9905 | Use after free in Accessibility |
| CVE-2026-9906 | Out of bounds write in GPU |
| CVE-2026-9907 | Out of bounds read in Dawn |
| CVE-2026-9908 | Out of bounds read in ANGLE |
| CVE-2026-9909 | Integer overflow in Skia |
| CVE-2026-9910 | Out of bounds memory access in ANGLE |
| CVE-2026-9911 | Integer overflow in ANGLE |
| CVE-2026-9912 | Inappropriate implementation in GPU |
| CVE-2026-9913 | Inappropriate implementation in ANGLE |
| CVE-2026-9914 | Insufficient validation of untrusted input in ANGLE |
| CVE-2026-9915 | Heap buffer overflow in ANGLE |
| CVE-2026-9916 | Out of bounds write in ANGLE |
| CVE-2026-9917 | Uninitialized Use in WebGL |
| CVE-2026-9918 | Inappropriate implementation in Tint |
| CVE-2026-9919 | Out of bounds read in WebGL |
| CVE-2026-9920 | Uninitialized Use in GPU |
| CVE-2026-9921 | Uninitialized Use in WebGL |
| CVE-2026-9922 | Use after free in GPU |
| CVE-2026-9923 | Use after free in Skia |
| CVE-2026-9924 | Heap buffer overflow in ANGLE |
| CVE-2026-9925 | Use after free in ANGLE |
| CVE-2026-9926 | Heap buffer overflow in ANGLE |
| CVE-2026-9927 | Use after free in ANGLE |
| CVE-2026-9928 | Out of bounds read in ANGLE |
| CVE-2026-9929 | Inappropriate implementation in WebGL |
| CVE-2026-9930 | Out of bounds write in Dawn |
| CVE-2026-9931 | Use after free in GPU |
| CVE-2026-9932 | Use after free in ANGLE |
| CVE-2026-9933 | Use after free in Input |
| CVE-2026-9934 | Use after free in Aura |
| CVE-2026-9935 | Uninitialized Use in ANGLE |
| CVE-2026-9936 | Use after free in GFX |
| CVE-2026-9937 | Use after free in UI |
| CVE-2026-9938 | Inappropriate implementation in V8 |
| CVE-2026-9939 | Heap buffer overflow in WebCodecs |
| CVE-2026-9940 | Heap buffer overflow in ANGLE |
| CVE-2026-9941 | Use after free in ANGLE |
| CVE-2026-9942 | Uninitialized Use in ANGLE |
| CVE-2026-9943 | Out of bounds read in WebGL |
| CVE-2026-9944 | Uninitialized Use in ANGLE |
| CVE-2026-9945 | Use after free in Media |
| CVE-2026-9946 | Use after free in ANGLE |
| CVE-2026-9947 | Use after free in XML |
| CVE-2026-9948 | Use after free in Views |
| CVE-2026-9949 | Use after free in Core |
| CVE-2026-9950 | Insufficient validation of untrusted input in iOS |
| CVE-2026-9951 | Use after free in UI |
| CVE-2026-9952 | Use after free in WebAudio |
| CVE-2026-9953 | Out of bounds read in ANGLE |
| CVE-2026-9954 | Use after free in TabStrip |
| CVE-2026-9955 | Inappropriate implementation in iOS |
| CVE-2026-9956 | Use after free in iOS |
| CVE-2026-9957 | Use after free in PDF |
| CVE-2026-9958 | Use after free in PDFium |
| CVE-2026-9959 | Race in WebRTC |
| CVE-2026-9960 | Integer overflow in PDFium |
| CVE-2026-9961 | Use after free in SurfaceCapture |
| CVE-2026-9962 | Use after free in WebRTC |
| CVE-2026-9963 | Uninitialized Use in iOS |
| CVE-2026-9964 | Use after free in Bluetooth |
| CVE-2026-9965 | Out of bounds write in ANGLE |
| CVE-2026-9966 | Integer overflow in XML |
| CVE-2026-9967 | Out of bounds write in GPU |
| CVE-2026-9968 | Integer overflow in V8 |
| CVE-2026-9969 | Insufficient validation of untrusted input in ANGLE |
| CVE-2026-9970 | Use after free in WebGL |
| CVE-2026-9971 | Inappropriate implementation in iOS |
| CVE-2026-9972 | Uninitialized Use in Gamepad |
| CVE-2026-9973 | Out of bounds write in V8 |
| CVE-2026-9974 | Out of bounds write in GPU |
| CVE-2026-9975 | Out of bounds read and write in ANGLE |
| CVE-2026-9976 | Inappropriate implementation in USB |
| CVE-2026-9977 | Insufficient validation of untrusted input in WebShare |
| CVE-2026-9978 | Use after free in Glic |
| CVE-2026-9979 | Insufficient validation of untrusted input in Input |
| CVE-2026-9980 | Insufficient validation of untrusted input in Printing |
| CVE-2026-9981 | Inappropriate implementation in Skia |
| CVE-2026-9982 | Insufficient validation of untrusted input in ANGLE |
| CVE-2026-9983 | Type Confusion in Skia |
| CVE-2026-9984 | Use after free in UI |
| CVE-2026-9985 | Insufficient validation of untrusted input in Media |
| CVE-2026-9986 | Insufficient validation of untrusted input in OptimizationGuide |
| CVE-2026-9987 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-9988 | Use after free in WebRTC |
| CVE-2026-9989 | Inappropriate implementation in Media |
| CVE-2026-9990 | Use after free in WebAppInstalls |
| CVE-2026-9991 | Inappropriate implementation in Media |
| CVE-2026-9992 | Use after free in Network |
| CVE-2026-9993 | Use after free in Views |
| CVE-2026-9994 | Use after free in Core |
| CVE-2026-9995 | Use after free in WebXR |
| CVE-2026-9996 | Out of bounds read in WebRTC |
| CVE-2026-9997 | Use after free in Input |
| CVE-2026-9998 | Integer overflow in Skia |
| CVE-2026-9999 | Inappropriate implementation in ANGLE |
| CVE-2026-10000 | Use after free in Passwords |
| CVE-2026-10001 | Use after free in PerformanceManager |
| CVE-2026-10002 | Use after free in PDFium |
| CVE-2026-10003 | Use after free in Views |
| CVE-2026-10004 | Insufficient validation of untrusted input in Passwords |
| CVE-2026-10005 | Use after free in WebAppInstalls |
| CVE-2026-10006 | Race in WebAudio |
| CVE-2026-10007 | Use after free in SVG |
| CVE-2026-10008 | Uninitialized Use in GPU |
| CVE-2026-10009 | Integer overflow in Skia |
| CVE-2026-10010 | Inappropriate implementation in Input |
| CVE-2026-10011 | Inappropriate implementation in Skia |
| CVE-2026-10012 | Use after free in Skia |
| CVE-2026-10013 | Use after free in WebCodecs |
| CVE-2026-10014 | Use after free in WebMIDI |
| CVE-2026-10015 | Integer overflow in WTF |
| CVE-2026-10016 | Use after free in DOM |
| CVE-2026-10017 | Out of bounds read in Headless |
| CVE-2026-10018 | Integer overflow in ANGLE |
| CVE-2026-10019 | Integer overflow in ANGLE |
| CVE-2026-10020 | Insufficient validation of untrusted input in Skia |
| CVE-2026-10021 | Insufficient validation of untrusted input in USB |
| CVE-2026-10022 | Type Confusion in V8 |
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| Prisma Browser | < 148.18.4.217 | >= 148.18.4.217 |
Required Configuration for Exposure
No special configuration is required to be affected by this issue.
Severity: HIGH, Suggested Urgency: MODERATE
CVSS-BT: 8.4 / CVSS-B: 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:N/R:A/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Solution
| CVE | Prisma Browser |
|---|---|
| CVE-2026-8509 | 148.12.1.168 |
| CVE-2026-8510 | 148.12.1.168 |
| CVE-2026-8511 | 148.12.1.168 |
| CVE-2026-8512 | 148.12.1.168 |
| CVE-2026-8513 | 148.12.1.168 |
| CVE-2026-8514 | 148.12.1.168 |
| CVE-2026-8515 | 148.12.1.168 |
| CVE-2026-8516 | 148.12.1.168 |
| CVE-2026-8517 | 148.12.1.168 |
| CVE-2026-8518 | 148.12.1.168 |
| CVE-2026-8519 | 148.12.1.168 |
| CVE-2026-8520 | 148.12.1.168 |
| CVE-2026-8521 | 148.12.1.168 |
| CVE-2026-8522 | 148.12.1.168 |
| CVE-2026-8523 | 148.12.1.168 |
| CVE-2026-8524 | 148.12.1.168 |
| CVE-2026-8525 | 148.12.1.168 |
| CVE-2026-8526 | 148.12.1.168 |
| CVE-2026-8527 | 148.12.1.168 |
| CVE-2026-8528 | 148.12.1.168 |
| CVE-2026-8529 | 148.12.1.168 |
| CVE-2026-8530 | 148.12.1.168 |
| CVE-2026-8531 | 148.12.1.168 |
| CVE-2026-8532 | 148.12.1.168 |
| CVE-2026-8533 | 148.12.1.168 |
| CVE-2026-8534 | 148.12.1.168 |
| CVE-2026-8535 | 148.12.1.168 |
| CVE-2026-8536 | 148.12.1.168 |
| CVE-2026-8537 | 148.12.1.168 |
| CVE-2026-8538 | 148.12.1.168 |
| CVE-2026-8539 | 148.12.1.168 |
| CVE-2026-8540 | 148.12.1.168 |
| CVE-2026-8541 | 148.12.1.168 |
| CVE-2026-8542 | 148.12.1.168 |
| CVE-2026-8543 | 148.12.1.168 |
| CVE-2026-8544 | 148.12.1.168 |
| CVE-2026-8545 | 148.12.1.168 |
| CVE-2026-8546 | 148.12.1.168 |
| CVE-2026-8547 | 148.12.1.168 |
| CVE-2026-8548 | 148.12.1.168 |
| CVE-2026-8549 | 148.12.1.168 |
| CVE-2026-8550 | 148.12.1.168 |
| CVE-2026-8551 | 148.12.1.168 |
| CVE-2026-8552 | 148.12.1.168 |
| CVE-2026-8553 | 148.12.1.168 |
| CVE-2026-8554 | 148.12.1.168 |
| CVE-2026-8555 | 148.12.1.168 |
| CVE-2026-8556 | 148.12.1.168 |
| CVE-2026-8557 | 148.12.1.168 |
| CVE-2026-8558 | 148.12.1.168 |
| CVE-2026-8559 | 148.12.1.168 |
| CVE-2026-8560 | 148.12.1.168 |
| CVE-2026-8561 | 148.12.1.168 |
| CVE-2026-8562 | 148.12.1.168 |
| CVE-2026-8563 | 148.12.1.168 |
| CVE-2026-8564 | 148.12.1.168 |
| CVE-2026-8565 | 148.12.1.168 |
| CVE-2026-8566 | 148.12.1.168 |
| CVE-2026-8567 | 148.12.1.168 |
| CVE-2026-8568 | 148.12.1.168 |
| CVE-2026-8569 | 148.12.1.168 |
| CVE-2026-8570 | 148.12.1.168 |
| CVE-2026-8571 | 148.12.1.168 |
| CVE-2026-8572 | 148.12.1.168 |
| CVE-2026-8573 | 148.12.1.168 |
| CVE-2026-8574 | 148.12.1.168 |
| CVE-2026-8575 | 148.12.1.168 |
| CVE-2026-8576 | 148.12.1.168 |
| CVE-2026-8577 | 148.12.1.168 |
| CVE-2026-8578 | 148.12.1.168 |
| CVE-2026-8579 | 148.12.1.168 |
| CVE-2026-8580 | 148.12.1.168 |
| CVE-2026-8581 | 148.12.1.168 |
| CVE-2026-8582 | 148.12.1.168 |
| CVE-2026-8583 | 148.12.1.168 |
| CVE-2026-8584 | 148.12.1.168 |
| CVE-2026-8585 | 148.12.1.168 |
| CVE-2026-8586 | 148.12.1.168 |
| CVE-2026-8587 | 148.12.1.168 |
| CVE-2026-9110 | 148.18.2.179 |
| CVE-2026-9111 | 148.18.2.179 |
| CVE-2026-9112 | 148.18.2.179 |
| CVE-2026-9113 | 148.18.2.179 |
| CVE-2026-9114 | 148.18.2.179 |
| CVE-2026-9115 | 148.18.2.179 |
| CVE-2026-9116 | 148.18.2.179 |
| CVE-2026-9117 | 148.18.2.179 |
| CVE-2026-9118 | 148.18.2.179 |
| CVE-2026-9120 | 148.18.2.179 |
| CVE-2026-9121 | 148.18.2.179 |
| CVE-2026-9123 | 148.18.2.179 |
| CVE-2026-9124 | 148.18.2.179 |
| CVE-2026-9126 | 148.18.2.179 |
| CVE-2026-10000 | 148.18.4.217 |
| CVE-2026-10001 | 148.18.4.217 |
| CVE-2026-10002 | 148.18.4.217 |
| CVE-2026-10003 | 148.18.4.217 |
| CVE-2026-10004 | 148.18.4.217 |
| CVE-2026-10005 | 148.18.4.217 |
| CVE-2026-10006 | 148.18.4.217 |
| CVE-2026-10007 | 148.18.4.217 |
| CVE-2026-10008 | 148.18.4.217 |
| CVE-2026-10009 | 148.18.4.217 |
| CVE-2026-10010 | 148.18.4.217 |
| CVE-2026-10011 | 148.18.4.217 |
| CVE-2026-10012 | 148.18.4.217 |
| CVE-2026-10013 | 148.18.4.217 |
| CVE-2026-10014 | 148.18.4.217 |
| CVE-2026-10015 | 148.18.4.217 |
| CVE-2026-10016 | 148.18.4.217 |
| CVE-2026-10017 | 148.18.4.217 |
| CVE-2026-10018 | 148.18.4.217 |
| CVE-2026-10019 | 148.18.4.217 |
| CVE-2026-10020 | 148.18.4.217 |
| CVE-2026-10021 | 148.18.4.217 |
| CVE-2026-10022 | 148.18.4.217 |
| CVE-2026-9872 | 148.18.4.217 |
| CVE-2026-9873 | 148.18.4.217 |
| CVE-2026-9874 | 148.18.4.217 |
| CVE-2026-9875 | 148.18.4.217 |
| CVE-2026-9876 | 148.18.4.217 |
| CVE-2026-9877 | 148.18.4.217 |
| CVE-2026-9878 | 148.18.4.217 |
| CVE-2026-9879 | 148.18.4.217 |
| CVE-2026-9880 | 148.18.4.217 |
| CVE-2026-9881 | 148.18.4.217 |
| CVE-2026-9882 | 148.18.4.217 |
| CVE-2026-9883 | 148.18.4.217 |
| CVE-2026-9884 | 148.18.4.217 |
| CVE-2026-9885 | 148.18.4.217 |
| CVE-2026-9886 | 148.18.4.217 |
| CVE-2026-9887 | 148.18.4.217 |
| CVE-2026-9888 | 148.18.4.217 |
| CVE-2026-9889 | 148.18.4.217 |
| CVE-2026-9890 | 148.18.4.217 |
| CVE-2026-9891 | 148.18.4.217 |
| CVE-2026-9892 | 148.18.4.217 |
| CVE-2026-9893 | 148.18.4.217 |
| CVE-2026-9894 | 148.18.4.217 |
| CVE-2026-9895 | 148.18.4.217 |
| CVE-2026-9896 | 148.18.4.217 |
| CVE-2026-9897 | 148.18.4.217 |
| CVE-2026-9898 | 148.18.4.217 |
| CVE-2026-9899 | 148.18.4.217 |
| CVE-2026-9900 | 148.18.4.217 |
| CVE-2026-9901 | 148.18.4.217 |
| CVE-2026-9902 | 148.18.4.217 |
| CVE-2026-9903 | 148.18.4.217 |
| CVE-2026-9904 | 148.18.4.217 |
| CVE-2026-9905 | 148.18.4.217 |
| CVE-2026-9906 | 148.18.4.217 |
| CVE-2026-9907 | 148.18.4.217 |
| CVE-2026-9908 | 148.18.4.217 |
| CVE-2026-9909 | 148.18.4.217 |
| CVE-2026-9910 | 148.18.4.217 |
| CVE-2026-9911 | 148.18.4.217 |
| CVE-2026-9912 | 148.18.4.217 |
| CVE-2026-9913 | 148.18.4.217 |
| CVE-2026-9914 | 148.18.4.217 |
| CVE-2026-9915 | 148.18.4.217 |
| CVE-2026-9916 | 148.18.4.217 |
| CVE-2026-9917 | 148.18.4.217 |
| CVE-2026-9918 | 148.18.4.217 |
| CVE-2026-9919 | 148.18.4.217 |
| CVE-2026-9920 | 148.18.4.217 |
| CVE-2026-9921 | 148.18.4.217 |
| CVE-2026-9922 | 148.18.4.217 |
| CVE-2026-9923 | 148.18.4.217 |
| CVE-2026-9924 | 148.18.4.217 |
| CVE-2026-9925 | 148.18.4.217 |
| CVE-2026-9926 | 148.18.4.217 |
| CVE-2026-9927 | 148.18.4.217 |
| CVE-2026-9928 | 148.18.4.217 |
| CVE-2026-9929 | 148.18.4.217 |
| CVE-2026-9930 | 148.18.4.217 |
| CVE-2026-9931 | 148.18.4.217 |
| CVE-2026-9932 | 148.18.4.217 |
| CVE-2026-9933 | 148.18.4.217 |
| CVE-2026-9934 | 148.18.4.217 |
| CVE-2026-9935 | 148.18.4.217 |
| CVE-2026-9936 | 148.18.4.217 |
| CVE-2026-9937 | 148.18.4.217 |
| CVE-2026-9938 | 148.18.4.217 |
| CVE-2026-9939 | 148.18.4.217 |
| CVE-2026-9940 | 148.18.4.217 |
| CVE-2026-9941 | 148.18.4.217 |
| CVE-2026-9942 | 148.18.4.217 |
| CVE-2026-9943 | 148.18.4.217 |
| CVE-2026-9944 | 148.18.4.217 |
| CVE-2026-9945 | 148.18.4.217 |
| CVE-2026-9946 | 148.18.4.217 |
| CVE-2026-9947 | 148.18.4.217 |
| CVE-2026-9948 | 148.18.4.217 |
| CVE-2026-9949 | 148.18.4.217 |
| CVE-2026-9950 | 148.18.4.217 |
| CVE-2026-9951 | 148.18.4.217 |
| CVE-2026-9952 | 148.18.4.217 |
| CVE-2026-9953 | 148.18.4.217 |
| CVE-2026-9954 | 148.18.4.217 |
| CVE-2026-9955 | 148.18.4.217 |
| CVE-2026-9956 | 148.18.4.217 |
| CVE-2026-9957 | 148.18.4.217 |
| CVE-2026-9958 | 148.18.4.217 |
| CVE-2026-9959 | 148.18.4.217 |
| CVE-2026-9960 | 148.18.4.217 |
| CVE-2026-9961 | 148.18.4.217 |
| CVE-2026-9962 | 148.18.4.217 |
| CVE-2026-9963 | 148.18.4.217 |
| CVE-2026-9964 | 148.18.4.217 |
| CVE-2026-9965 | 148.18.4.217 |
| CVE-2026-9966 | 148.18.4.217 |
| CVE-2026-9967 | 148.18.4.217 |
| CVE-2026-9968 | 148.18.4.217 |
| CVE-2026-9969 | 148.18.4.217 |
| CVE-2026-9970 | 148.18.4.217 |
| CVE-2026-9971 | 148.18.4.217 |
| CVE-2026-9972 | 148.18.4.217 |
| CVE-2026-9973 | 148.18.4.217 |
| CVE-2026-9974 | 148.18.4.217 |
| CVE-2026-9975 | 148.18.4.217 |
| CVE-2026-9976 | 148.18.4.217 |
| CVE-2026-9977 | 148.18.4.217 |
| CVE-2026-9978 | 148.18.4.217 |
| CVE-2026-9979 | 148.18.4.217 |
| CVE-2026-9980 | 148.18.4.217 |
| CVE-2026-9981 | 148.18.4.217 |
| CVE-2026-9982 | 148.18.4.217 |
| CVE-2026-9983 | 148.18.4.217 |
| CVE-2026-9984 | 148.18.4.217 |
| CVE-2026-9985 | 148.18.4.217 |
| CVE-2026-9986 | 148.18.4.217 |
| CVE-2026-9987 | 148.18.4.217 |
| CVE-2026-9988 | 148.18.4.217 |
| CVE-2026-9989 | 148.18.4.217 |
| CVE-2026-9990 | 148.18.4.217 |
| CVE-2026-9991 | 148.18.4.217 |
| CVE-2026-9992 | 148.18.4.217 |
| CVE-2026-9993 | 148.18.4.217 |
| CVE-2026-9994 | 148.18.4.217 |
| CVE-2026-9995 | 148.18.4.217 |
| CVE-2026-9996 | 148.18.4.217 |
| CVE-2026-9997 | 148.18.4.217 |
| CVE-2026-9998 | 148.18.4.217 |
| CVE-2026-9999 | 148.18.4.217 |
Workarounds and Mitigations
No known workarounds exist for this issue.
CPE Applicability
- cpe:2.3:a:palo_alto_networks:prisma_browser:*:*:*:*:*:*:*:* is vulnerable from (including)148.18.4 and up to (excluding)148.18.4.217
Timeline
Initial Publication