GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

Plan PatchCVSS 7.2CVE-2026-0295Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A race condition in the Palo Alto Networks GlobalProtect client on macOS allows a locally authenticated low-privileged attacker to escalate privileges to root. The vulnerability exists in versions below 6.3.3-h14 (6.3.3-1121) and 6.2.8-h13 (6.2.8-1045). GlobalProtect on Linux, Windows, iOS, Android, and Chrome OS are not affected.

What this means
What could happen
A locally authenticated user on a macOS system running the GlobalProtect client could exploit a race condition to gain root-level access, allowing them to modify VPN configuration, intercept traffic, or compromise the entire endpoint.
Who's at risk
Organizations whose employees use macOS laptops with Palo Alto GlobalProtect VPN client. IT teams managing remote workforce endpoints, particularly those in utilities, water authorities, and critical infrastructure where remote access is required. This affects workstations and laptops, not OT servers or embedded systems.
How it could be exploited
An attacker with a local user account on a macOS machine must wait for a specific timing window during GlobalProtect app startup or operation, then execute a race condition attack to replace or modify system files that the app accesses with elevated privileges. Once the race condition is triggered, the attacker gains root-level code execution.
Prerequisites
  • Local user account on macOS system
  • GlobalProtect app version below 6.3.3-h14 or 6.2.8-h13 running on macOS
  • Ability to trigger GlobalProtect startup or specific app operations
Local privilege escalation (not remote)Requires local user account and authenticated accessRace condition (requires specific timing, lower practical exploit probability)
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on macOS6.3.3-h14 (6.3.3-1121) on macOS+
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on macOS6.2.8-h13 (6.2.8-1045) on macOS+
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

GlobalProtect App
HOTFIXUpdate GlobalProtect app to version 6.3.3-h14 (6.3.3-1121) or later on all macOS systems
HOTFIXUpdate GlobalProtect app to version 6.2.8-h13 (6.2.8-1045) or later for systems on the 6.2 branch
Long-term hardening
0/1
HARDENINGRestrict local user account creation and privileges on macOS endpoints to reduce the number of users who could attempt exploitation
API: /api/v1/advisories/7cb69ada-a2fa-4dad-b89f-6fb78a96a2d9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.