Description
A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. 
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2025-08-13
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24585 A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
History

Tue, 21 Oct 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
F5 big-ip Access Policy Manager
F5 big-ip Access Policy Manager Client
CPEs cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_access_policy_manager_client:7.2.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
F5 big-ip Access Policy Manager
F5 big-ip Access Policy Manager Client

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 big-ip
F5 big-ip Edge Client
Vendors & Products F5
F5 big-ip
F5 big-ip Edge Client

Wed, 13 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 15:00:00 +0000

Type Values Removed Values Added
Description A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title BIG-IP APM VPN web client for macOS vulnerability
Weaknesses CWE-353
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apple Macos
F5 Big-ip Big-ip Access Policy Manager Big-ip Access Policy Manager Client Big-ip Edge Client
cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-02-26T17:48:40.742Z

Reserved: 2025-07-29T17:12:25.024Z

Link: CVE-2025-48500

cve-icon Vulnrichment

Updated: 2025-08-13T15:02:52.785Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-13T15:15:32.533

Modified: 2025-10-21T18:29:37.640

Link: CVE-2025-48500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-13T21:47:01Z

Weaknesses