--- type: Addressed product: GlobalProtect version: 6.2.8-h3 --- ## GPC-23604 Fixed an issue where GlobalProtect users were not automatically prompted for authentication on public Wi-Fi networks with a captive portal. ## GPC-23520 Fixed an issue where new GlobalProtect users were unable to connect to the GlobalProtect app. The app got stuck in **Connecting** stage and stopped working when redirected to the embedded browser. ## GPC-23496 Fixed an issue where the GlobalProtect app's **Connect** button did not work as expected preventing users from connecting or changing gateways. ## GPC-23440 Fixed an issue where Okta FastPass authentication did not work with GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app did not open for the additional authentication prompt. ## GPC-23466 Fixed an issue where, when the GlobalProtect app was installed on devices running Windows OS and macOS, the Captive Portal detection message briefly appeared and disappeared when the Captive Portal exception timeout was set to 0. ## GPC-23432 Fixed an issue where the GlobalProtect app version 6.3.3 intermittently got stuck on the **finding best gateway** status ## GPC-23365 Fixed an issue where, when the GlobalProtect app was installed on Windows machines, the app intermittently disconnected and then reconnected with the error message **Failed to create exclude route**. ## GPC-23301 Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was installed on Windows 10 devices, the app deleted the predefined proxy PAC file configuration whenever the app got disconnected regardless of whether the disconnection was initiated manually or occurred automatically due to a timeout. ## GPC-23263 Fixed an issue where after upgrading to GlobalProtect app version 6.3.3, the app did not save the username in the embedded browser when "**Save Username** was enabled. ## GPC-23218 Fixed an issue where, when using the GlobalProtect app with an embedded browser, interrupting or canceling the SAML authentication prompt terminated the pre-logon tunnel, potentially allowing full internet access even when enforcer was enabled for the user-logon profile. With default browser, the pre-logon tunnel remained active when the SAML authentication prompt was interrupted. ## GPC-23125 Fixed an issue where GlobalProtect did not remove older versions of the WebView2 component from the %LOCALAPPDATA%\Palo Alto Networks\GlobalProtect\GPAEdge directory, which led to unnecessary disk space consumption over time. ## GPC-22989 Fixed an issue where the GlobalProtect app intermittently stopped sending HIP reports while connected to the gateway. ## GPC-22979 Fixed an issue where, after upgrading to GlobalProtect app version 6.2.6, the PanGPA application got stuck in **Connecting** 'state and then got terminated unexpectedly. ## GPC-22541 Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA) would stop working when the device was locked. The crash occurred when an expired authentication triggered a persistent smartcard login dialog during sleep, leading to excessive memory swapping and a crypt32.dll failure.