
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59489 is an argument injection and untrusted search path vulnerability in the Unity Runtime that allows attackers to load library code from an unintended location, potentially enabling arbitrary code execution and data exfiltration. It affects applications built with Unity Editor versions from approximately 2017.1 through 6000.3 (before the fixed releases), targeting Android, Windows, macOS, and Linux platforms. The vulnerability was publicly disclosed on October 3, 2025, with Unity's official security advisory published shortly after. It carries a CVSS v3.1 base score of 7.4 (High) per NVD, though ENISA rates it 8.4 (Unity Advisory, MSRC).
The root cause is classified under CWE-426 (Untrusted Search Path) and CWE-88 (Improper Neutralization of Argument Delimiters — Argument Injection). The Unity Runtime fails to properly validate or sanitize arguments that influence library search paths, allowing an adversary to manipulate which library code is loaded at runtime. Exploitation requires local access (attack vector: local) but no privileges or user interaction, and the high attack complexity reflects the need for specific environmental conditions. A detailed technical write-up by Flatt Security describes the mechanics of the arbitrary code execution path in the Unity Runtime (Flatt Security). Notably, updating Unity Editor alone does not remediate the vulnerability — affected applications must be rebuilt and redeployed with a patched Unity version (Unity Advisory).
Successful exploitation can result in arbitrary code execution on the machine running a vulnerable Unity-built application, as well as exfiltration of confidential information from that system. All three CIA pillars are rated High: confidentiality, integrity, and availability are fully compromised upon successful exploitation. The vulnerability affects a massive ecosystem — Unity powers an estimated 70% of top mobile games, meaning hundreds of millions of end-user devices running unpatched applications across Android, Windows, macOS, and Linux are potentially at risk (Unity Advisory, SecurityWeek). Microsoft confirmed that several of its own products built on Unity — including Fallout Shelter, Hearthstone, The Elder Scrolls: Blades, and Microsoft Mesh applications — were affected (MSRC).
.dll, .so, or .dylib) in the attacker-controlled path that the Unity Runtime will load instead of the legitimate library..dll, .so, or .dylib files placed in directories adjacent to or within Unity application installation paths; newly created files in application data directories with names matching legitimate Unity runtime libraries.Unity released fixed versions across all affected branches; key patched versions include Unity 6000.0.58f2 (LTS), 6000.1.17f1, 6000.2.6f2, 6000.3.0b4, 2022.3.62f2 (LTS), 2021.3.45f2 (LTS), 2019.4.41f1 (LTS), and others — developers must upgrade to the appropriate fixed Unity Editor version and rebuild and redeploy all affected applications, as updating the editor alone does not protect end users (Unity Advisory). Microsoft advised users to temporarily uninstall affected games, keep Microsoft Defender up to date, and install all available app updates; Steam deployed client-side mitigations as a temporary measure while developers patch their games (MSRC, BleepingComputer). End users should enable automatic updates for all games and applications and prioritize updating Unity-based titles, particularly those on Android where the risk of crypto wallet access was highlighted by security researchers.
Unity issued an urgent security advisory urging developers to take immediate action, and both Microsoft and Valve (Steam) issued public warnings to gamers — a rare coordinated response from major platform holders (Unity Advisory, SecurityWeek). The vulnerability generated significant community discussion on Reddit (r/Unity3D, r/Steam, r/netsec), Hacker News, and Bluesky, with many developers scrambling to understand the patching process and players asking which games were affected. Security outlets including BleepingComputer, The Record, Kaspersky, Neowin, TechRadar, and SC World covered the story extensively, with some framing it as an "8-year-old" flaw given Unity 2017's inclusion in the affected range (BleepingComputer, The Record). Flatt Security, the discovering research team, published a detailed technical blog post that drove much of the community awareness (Flatt Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."