FortiClientMacOS - Missing signature verification

Summary

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.

Version Affected Solution
FortiClientMac 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientMac 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientMac 7.0 7.0.0 through 7.0.10 Migrate to a fixed release
FortiClientMac 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Mykola Grymalyuk from RIPEDA Consulting for reporting this vulnerability under responsible disclosure.

Timeline

2024-11-12: Initial publication