PT-2025-40457 · Unity Technologies · Unity Runtime
Ryotak
·
Published
2025-10-03
·
Updated
2025-10-06
·
CVE-2025-59489
CVSS v3.1
7.4
7.4
High
Base vector | Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unity versions 2017.1 and later
Description
A significant security vulnerability (CVE-2025-59489) exists in the Unity runtime, potentially allowing arbitrary code execution. This issue stems from an untrusted search path, enabling the loading of malicious code through crafted command-line arguments. While primarily a local code execution risk, remote exploitation is possible under specific conditions on Android. Approximately 70% of mobile games are estimated to be affected. No active exploitation has been reported, but the vulnerability has existed since 2017. The vulnerability affects applications built for Windows, Android, macOS, and Linux. Platforms like iOS, Xbox, and Meta Horizon OS are not affected. API endpoints are not directly involved in the vulnerability, but the issue relates to how Unity handles command-line arguments that can influence file loading.
Recommendations
Update to the latest patched Unity Editor version and rebuild projects. If rebuilding is not feasible, use the Unity Application Patcher to patch existing builds. If applications use anti-cheat or tamper protection, rebuilding is required. Ensure automatic updates are enabled for games and applications.
Fix
RCE
LPE
Untrusted Search Path
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Related Identifiers
CVE-2025-59489
Affected Products
Unity Runtime
References · 68
- https://nvd.nist.gov/vuln/detail/CVE-2025-59489 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59489 · Vendor Advisory
- https://twitter.com/grok/status/1974285626171363794 · Twitter Post
- https://youtu.be/7phGa0_mFnc · Reddit Post
- https://twitter.com/grok/status/1974244015542530535 · Twitter Post
- https://unity.com/security#security-updates-and-patches · Note
- https://reddit.com/r/u_GuardingPearSoftware/comments/1nx3ipt/unitys_big_scare_what_you_need_to_know_about · Reddit Post
- https://twitter.com/2000_mondo/status/1974155656761651282 · Twitter Post
- https://twitter.com/betterhn20/status/1974162400502034939 · Twitter Post
- https://twitter.com/GuardingPearSof/status/1974146731102056767 · Twitter Post
- https://twitter.com/flatt_sec_en/status/1973969808539750543 · Twitter Post
- https://twitter.com/shidygames/status/1974404518344335818 · Twitter Post
- https://twitter.com/read2earnxyz/status/1974214601152844094 · Twitter Post
- https://twitter.com/pHo9UBenaA/status/1974365312146636927 · Twitter Post
- https://twitter.com/wickedplayer494/status/1974190928744362396 · Twitter Post