GlobalProtect: Authenticated Code Injection Through Wildcard on macOS (CVE-2025-4232)
BACKGROUND
CVSSv3 Score: Base 8.5 High
Palo Alto Networks has issued an advisory regarding a critical vulnerability, tracked as CVE-2025-4232,
affecting its GlobalProtect app on macOS.
An improper neutralization of wildcard characters exists in the log collection feature of the GlobalProtect
app. This flaw can be exploited by an authenticated but non-administrative user to execute arbitrary code
with root privileges.
Exploiting this vulnerability can result in privilege escalation to root, granting the attacker full control over
the aected macOS system. This includes the ability to install programs, view, modify, or delete data, and
create new user accounts with full privileges.
IMPACT
- Successful exploitation may allow privilege escalation to root access, granting the attacker full
control over the aected macOS system - Ability to install software, view, modify or delete data, and create new user accounts with full
privileges.
SYSTEMS AFFECTED
| Affected Versions | Affected Minor Versions | Fixed Versions | |
| 1 | GlobalProtect App 6.3 on macOS | 6.3.0 through 6.3.2 | Upgrade to 6.3.3 or later. |
| 2 | GlobalProtect App 6.2 on macOS | 6.2.0 through 6.2.8-h2 | Upgrade to 6.2.8-h2 [ETA June 2025] or 6.3.3 or later. |
| 3 | GlobalProtect App 6.1 on macOS | Upgrade to 6.2.8-h2 [ETA June 2025] or 6.3.3 or later. | |
| 4 | GlobalProtect App 6.0 on macOS | Upgrade to 6.2.8-h2 [ETA June 2025] or 6.3.3 or later |
RECOMMENDATIONS
- Apply updates to the aected versions as soon as possible.
- Upgrade to the fixed or latest version released by Palo Alto Networks.
REFERENCES
https://security.paloaltonetworks.com/CVE-2025-4232