Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HApple macOS
OSAppleall versionsGematik Authenticator
APPGematik4.12.0 – 4.16.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCECommand Injection
CWE
Related vulnerabilities
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product
Apple — memory corruption (RCE) w przetwarzaniu strumieni audio
CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach