Executive brief
A security flaw in Fortinet's networking software allows users on Apple devices to bypass DNS filtering protections. This means that restricted or malicious websites that should be blocked by the corporate firewall may remain accessible to these devices. While it does not directly lead to data theft, it undermines the security policies intended to protect the network from harmful content.
Technical details
The vulnerability (CWE-358) exists in the DNS filtering component of FortiOS and FortiProxy. It is triggered by DNS type 65 (HTTPS) resource record requests, which are commonly used by Apple devices for encrypted client hello and HTTP/3 discovery. Because these specific record types are not correctly handled by the security check, an unauthenticated attacker on the network can bypass configured DNS filters to reach restricted domains. The issue affects multiple versions of FortiOS, FortiProxy, and FortiSASE. Patches are available in FortiOS 7.6.1, 7.4.8, and 7.2.11, and FortiProxy 7.6.2 and 7.4.9.
Affected products
- Fortinet FortiOS 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0 all versions, 6.4 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions
- Fortinet FortiSASE 24.4.a
Timeline
- 2025-07-08: disclosed: Initial publication by Fortinet
- 2025-07-08: advisory: Fortinet advisory FG-IR-24-053 published