{"id":"CVE-2026-0236","title":"A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to …","summary":"A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"paloaltonetworks","product":"prisma_browser","affected":["prisma_browser < 146.10.7.154"],"patched":["prisma_browser 146.10.7.154"],"published":"2026-05-13","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0236","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0236","label":"psirt@paloaltonetworks.com"}],"tags":["nvd"],"epss":0.00158,"epssPercentile":0.05367,"ingestedAt":"2026-07-13T14:27:26.653Z","slug":"CVE-2026-0236","body":"## Overview\n\nA code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.\n\n## Affected\n\n- `prisma_browser < 146.10.7.154`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `prisma_browser 146.10.7.154`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}