Palo Alto Networks Prisma Access Browser (PAB) - Bypassing screenshot restrictions via Windows Display Affinity manipulation

CVE ID

CVE-2025-4617

Description

An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser.

Tested Versions

131.109.2963.1

Details

Palo Alto Networks Prisma Access Browser (PAB) is an enterprise browser which emerged as a critical security control for organisations seeking to protect sensitive data and enforce security policies in cloud-first environments.

Timeline

  • 2024-12-30 - Vendor Disclosure
  • 2025-06-11 - Vendor Patched
  • 2025-11-14 - Public Release

Credit

Discovered by Tan Inn Fung, Yu Ann Ong, Zhang Bosen from the GovTech Cybersecurity Group.