GlobalProtect App
CVE-2026-0295: Local Privilege Escalation via Race Condition on macOS
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| GlobalProtect App (macOS) 6.3 | 6.3.3-h14 or later |
| GlobalProtect App (macOS) 6.2 | 6.2.8-h13 or later |
| GlobalProtect App (macOS) 6.0 | 6.0.15 or later |
| GlobalProtect App (Linux, Windows, iOS, Android, Chrome OS) | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Am I affected?
No special configuration is required to be affected by this issue.
Workarounds
No known workarounds or mitigations exist for this issue.
Exploitation
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.