Palo Alto Networks has released a critical security update for the Prisma Access Browser to address several vulnerabilities found in its Chromium engine foundation. This update, designated as PAN-SA-2024-0007, replaces the previous Talon Browser and integrates crucial fixes from the latest Chromium patches.
The identified issues primarily involve “use after free” vulnerabilities, type confusion, and inadequate data validation within key Chromium components like V8, Media Stream, and WebAudio. These flaws could potentially enable attackers to run arbitrary code, compromising the affected systems’ confidentiality, integrity, and availability.
Details:
- Severity: Critical (CVSSv4.0 Base Score: 8.6)
- Urgency: Moderate
- Response Required: Low
- Recovery: Automatic
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction Required: Yes
Affected Versions:
- Prisma Access Browser: Versions prior to 126.183.2844.1
- Safe Versions: 127.100.2858.4 and later
Users should promptly upgrade to Prisma Access Browser version 127.100.2858.4 or newer to address these security issues. The update includes fixes for all relevant CVEs and bolsters overall browser security.
Additional Vulnerabilities:
Alongside the Prisma Access Browser update, Palo Alto Networks has addressed several other security concerns:
- CVE-2024-5914: A command injection vulnerability in the Cortex XSOAR CommonScripts pack affects versions earlier than 1.12.33, potentially allowing unauthenticated attackers to execute arbitrary commands within an integration container.
- CVE-2024-5915: Affects the GlobalProtect App on Windows, causing local privilege escalation in versions before 6.3.1. This vulnerability permits local users to run programs with elevated privileges.
- CVE-2024-5916: Involves cleartext exposure of external system secrets in PAN-OS, affecting versions 11.0 prior to 11.0.4 and 10.2 prior to 10.2.8. This issue enables local administrators to reveal external system secrets, passwords, and tokens.
Timeline:
- August 14, 2024: Initial release of the vulnerability advisory.
- August 15, 2024: Clarification on the specific affected and unaffected versions.
For more details on the addressed CVEs, users can review the Chromium stable channel updates from July and August 2024. These updates provide insight into the security enhancements made to the Prisma Access Browser to mitigate potential threats.



