Palo Alto Networks Prisma Access Browser (PAB) - Bypassing download restrictions via Chromium disk cache extraction

CVE ID

CVE-2025-4233

Description

A user denied the ability to download a file through PAB’s interface could in some cases retrieve it from the cache, effectively bypassing the download restriction.

Tested Versions

131.109.2963.1

Details

Palo Alto Networks Prisma Access Browser (PAB) is an enterprise browser which emerged as a critical security control for organisations seeking to protect sensitive data and enforce security policies in cloud-first environments.

Timeline

  • 2024-12-30 - Vendor Disclosure
  • 2025-06-11 - Vendor Patched
  • 2025-06-12 - Public Release

Credit

Discovered by Tan Inn Fung, Yu Ann Ong, Zhang Bosen from the GovTech Cybersecurity Group.