GlobalProtect App: Non Admin User Can Disable the GlobalProtect App

MonitorCVSS 6.8CVE-2025-0140Jul 9, 2025
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Exploitability
Unlikely to be exploited — EPSS score 0.0%
Affected products (3)
2 with fix1 pending
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h1 (6.3.3-c650) on macOS6.3.3-h1 (6.3.3-c650) on macOS+
GlobalProtect AppBelow 6.2.8-h2 (6.2.8-c243) on macOS6.2.8-h2 (6.2.8-c243) on macOS+
GlobalProtect UWP AppAll on macOSNo fix yet
API: /api/v1/advisories/35f97619-ac8b-4260-a7ba-d0d1756e630e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.