Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)

A security flaw in the GlobalProtect app on macOS lets a low-level user gain full administrative access. This means someone with basic access to your Mac could potentially take control of the system. The issue is due to a timing problem in the software that can be exploited locally without needing another person's help.

Published 12/8/2026, 4:00:00 pmVerified 12/8/2026, 6:30:32 pmRevision 1
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security flaw in the GlobalProtect app on macOS lets a low-level user gain full administrative access. This means someone with basic access to your Mac could potentially take control of the system. The issue is due to a timing problem in the software that can be exploited locally without needing another person's help.

Technical explanation

How the issue affects the environment

The vulnerability is a race condition (CWE-362) in the Palo Alto Networks GlobalProtect client on macOS. It allows a locally authenticated attacker with low privileges to escalate them to root via improper synchronization during concurrent operations. The weakness relates to a Time-of-Check to Time-of-Use (TOCTOU) issue (CAPEC-29) where the app fails to securely handle shared resources. This flaw is specific to macOS versions of GlobalProtect, affecting versions before 6.3.3-h14, 6.2.8-h13, and 6.0.15 respectively. Other operating systems are unaffected. Exploitation requires local access with low privileges but no user interaction is needed.

Operational impact

Why teams should care

This vulnerability could enable an attacker who already has limited access to a Mac to gain full administrative rights. This could compromise the confidentiality and integrity of the system, allowing unauthorized changes or access to sensitive data. There is no known active exploitation currently, but the impact of a successful attack is high, making timely upgrades critical to prevent possible damage or breaches.

Immediate action

To remediate this issue, update the GlobalProtect app on macOS to the fixed versions: 6.3.3-h14 or later for 6.3 series, 6.2.8-h13 or later for 6.2 series, and 6.0.15 or later for 6.0 series. These updates address the race condition and prevent the local privilege escalation.

Affected and fixed releases

Affected versionsGlobalProtect App 6.3.0 through 6.3.3-h13 on macOS, GlobalProtect App 6.2.0 through 6.2.8-h12 on macOS, GlobalProtect App 6.0.0 through 6.0.14 on macOS
Fixed versionsGlobalProtect App 6.3.3-h14 (6.3.3-1121) or later on macOS, GlobalProtect App 6.2.8-h13 (6.2.8-1045) or later on macOS, GlobalProtect App 6.0.15 or later on macOS

Temporary risk reduction

No known workarounds or mitigations exist for this issue according to the official source. Immediate application of the patch is recommended.

Evidence and validation checklist

  • Race condition allowing local privilege escalation on macOS
  • Impacts GlobalProtect app versions prior to fixed releases
  • No user interaction required to exploit
  • Attack vector is local with low privileges needed
  • No impact on GlobalProtect clients for other operating systems
  • No known workarounds exist
  • Official patches released and recommended

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source