Local Privilege Escalation in LaunchDaemon

Summary

An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking.

Version Affected Solution
FortiClientMac 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiClientMac 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above
FortiClientMac 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Isaac Ordonez from Mann Consulting for reporting this vulnerability under responsible disclosure.

Timeline

2025-10-14: Initial publication