Missing signature verification for FortiClient.app

Summary

An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer may allow a local user to escalate their privileges via FortiClient related executables.

Version Affected Solution
FortiClientMac 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.4 or above
FortiClientMac 7.2 7.2.0 through 7.2.9 Upgrade to 7.2.10 or above
FortiClientMac 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Mykola Grymalyuk from RIPEDA Consulting for reporting this vulnerability under responsible disclosure.

Timeline

2025-10-14: Initial publication