Fortinet FortiClient Mac Code Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A code injection vulnerability has been identified in Fortinet FortiClient for Mac, specifically in versions 7.4.0 to 7.4.3 and 7.2.1 to 7.2.8. This vulnerability allows an unauthenticated attacker to execute arbitrary code on the victim's host by tricking the user into visiting a malicious website.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code on the affected user's machine.

Remediation

Users can upgrade to FortiClient Mac version 7.4.4 or above, or version 7.2.9 or above, depending on their current version.

Added: Oct 14, 2025, 4:29 PM
Updated: Oct 14, 2025, 11:09 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.