PT-2025-41950 · Fortinet · Forticlientmac
Published
2025-10-14
·
Updated
2025-10-14
·
CVE-2025-31365
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FortiClientMac versions 7.2.1 through 7.2.8
FortiClientMac versions 7.4.0 through 7.4.3
Description
An issue exists in FortiClientMac that could allow an unauthenticated attacker to execute arbitrary code on a user's system. This is due to an improper control of code generation. The issue can be triggered by a user visiting a malicious website. The vulnerability is well-suited for phishing campaigns targeting macOS systems.
Recommendations
Update FortiClientMac to a version later than 7.2.8.
Update FortiClientMac to a version later than 7.4.3.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlientmac