Race condition in GlobalProtect App for macOS - CVE-2026-0295

 

Race condition in GlobalProtect App for macOS - CVE-2026-0295

Published: August 16, 2026


Vulnerability identifier: #VU143210
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0295
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges to root.

The vulnerability exists due to a race condition in the GlobalProtect client on macOS when handling concurrent operations on a shared resource. A local user can trigger the race condition to escalate privileges to root.

No special configuration is required to be affected by this issue.


Affected software

GlobalProtect App for macOS

How to mitigate CVE-2026-0295

Install security update from vendor's website.

GlobalProtect App for macOS - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14

External References

Related Security Bulletins