logo

Cato Networks macOS Client Vulnerability Enables Low-Privilege Code Execution

ID: 2dc8e5d5-685e-5958-bbb7-6bdbd999d98f

STIX ID: report--2dc8e5d5-685e-5958-bbb7-6bdbd999d98f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-04-30

Date Updated: 2026-04-22

Author: Divya

...
...

ZDI disclosed a TOCTOU local privilege escalation (ZDI-25-252, CVSS 7.8) in Cato Networks' macOS VPN client that allows low-privileged users to manipulate the installation process and execute code as root via the Helper service; ZDI published the advisory after Cato had not issued a patch, and organizations are advised to restrict local access, monitor helper services, audit deployments, and apply Cato’s patch once released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.