Skip to main content

GlobalProtect: Authenticated Code Injection Through Wildcard on macOS (CVE-2025-4232)

BACKGROUND


CVSSv3 Score: Base 8.5 High


Palo Alto Networks has issued an advisory regarding a critical vulnerability, tracked as CVE-2025-4232,
affecting its GlobalProtect app on macOS.

An improper neutralization of wildcard characters exists in the log collection feature of the GlobalProtect
app. This flaw can be exploited by an authenticated but non-administrative user to execute arbitrary code
with root privileges.

Exploiting this vulnerability can result in privilege escalation to root, granting the attacker full control over
the a􀆯ected macOS system. This includes the ability to install programs, view, modify, or delete data, and
create new user accounts with full privileges.

IMPACT

  • Successful exploitation may allow privilege escalation to root access, granting the attacker full
    control over the a􀆯ected macOS system
  • Ability to install software, view, modify or delete data, and create new user accounts with full
    privileges.

SYSTEMS AFFECTED

 Affected VersionsAffected Minor VersionsFixed Versions
1GlobalProtect App 6.3 on
macOS
6.3.0 through 6.3.2Upgrade to 6.3.3 or later.
2GlobalProtect App 6.2 on
macOS
6.2.0 through 6.2.8-h2Upgrade to 6.2.8-h2 [ETA June 2025] or
6.3.3 or later.
3GlobalProtect App 6.1 on
macOS
 Upgrade to 6.2.8-h2 [ETA June 2025] or
6.3.3 or later.
4GlobalProtect App 6.0 on
macOS
 Upgrade to 6.2.8-h2 [ETA June 2025] or
6.3.3 or later

RECOMMENDATIONS

  • Apply updates to the a􀆯ected versions as soon as possible.
  • Upgrade to the fixed or latest version released by Palo Alto Networks.
     

REFERENCES

https://security.paloaltonetworks.com/CVE-2025-4232

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.