Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)

A security flaw in the GlobalProtect VPN app for macOS allows a local attacker to gain higher system privileges, potentially giving them full control of the computer. This happens due to a timing flaw (race condition) in the software. Users should update to the latest fixed versions as soon as possible to prevent this.

Published 12/9/2026, 12:30:00 amVerified 16/9/2026, 6:45:41 amRevision 2
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security flaw in the GlobalProtect VPN app for macOS allows a local attacker to gain higher system privileges, potentially giving them full control of the computer. This happens due to a timing flaw (race condition) in the software. Users should update to the latest fixed versions as soon as possible to prevent this.

Technical explanation

How the issue affects the environment

The GlobalProtect app for macOS contains a race condition vulnerability (CWE-362) that enables a locally authenticated attacker with low privileges to escalate to root privileges. The issue arises from improper synchronization during concurrent execution, specifically a time-of-check to time-of-use (TOCTOU) race condition. This allows an attacker to manipulate the application state between validation and use phases, resulting in privilege escalation. The vulnerability affects versions 6.0.0 through 6.0.14, 6.2.0 through 6.2.8-h12, and 6.3.0 through 6.3.3-h13 on macOS, while other platforms are not affected.

Operational impact

Why teams should care

This vulnerability could lead to unauthorized full control of affected macOS systems running the GlobalProtect app, jeopardizing sensitive data confidentiality and system integrity. Attackers with local access could elevate their privileges to root, allowing installation of malicious software, data theft, or disruption of operations. No known active exploitation reported yet, but the risk warrants prompt remediation to protect enterprise environments.

Immediate action

Upgrade the GlobalProtect app on macOS to the respective fixed versions: 6.0.15 for 6.0.x users, 6.2.8-h13 for 6.2.x users, or 6.3.3-h14 for 6.3.x users. No special configuration changes are required to mitigate exposure.

Affected and fixed releases

Affected versionsGlobalProtect App 6.0.0 through 6.0.14 on macOS, GlobalProtect App 6.2.0 through 6.2.8-h12 on macOS, GlobalProtect App 6.3.0 through 6.3.3-h13 on macOS
Fixed versionsGlobalProtect App 6.0.15 or later on macOS, GlobalProtect App 6.2.8-h13 (6.2.8-1045) or later on macOS, GlobalProtect App 6.3.3-h14 (6.3.3-1121) or later on macOS

Temporary risk reduction

No known workarounds or mitigations exist for this issue beyond upgrading to a fixed version.

Evidence and validation checklist

  • Palo Alto Networks official security advisory for CVE-2026-0295
  • Description of race condition vulnerability and technical impact
  • Affected and fixed version details on macOS GlobalProtect app
  • Statement on no known workarounds
  • Disclosure and update timeline information

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source