Code injection in login window

Summary

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.

Version Affected Solution
FortiClientMac 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiClientMac 7.2 7.2.1 through 7.2.8 Upgrade to 7.2.9 or above
FortiClientMac 7.0 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.

Timeline

2025-10-14: Initial publication