CVE-2025-0135

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtectâ„¢ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*

History

27 Jun 2025, 16:50

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 19:15

Updated : 2025-06-27 16:50


NVD link : CVE-2025-0135

Mitre link : CVE-2025-0135

CVE.ORG link : CVE-2025-0135


JSON object : View

Products Affected

paloaltonetworks

  • globalprotect
CWE
CWE-266

Incorrect Privilege Assignment