PT-2025-40457 · Unity Technologies · Unity Runtime

Ryotak

·

Published

2025-06-04

·

Updated

2026-03-03

·

CVE-2025-59489

CVSS v3.1

7.4

High

AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unity versions 2017.1 through 6000.3
Description A critical vulnerability exists in the Unity Runtime, potentially allowing attackers to execute arbitrary code on systems running applications built with affected versions of the engine. This vulnerability, identified as CVE-2025-59489, stems from an untrusted search path that allows malicious libraries to be loaded. While primarily a local code execution issue, remote exploitation is possible under specific conditions on Android. The vulnerability affects applications built with Unity versions 2017.1 and later for Windows, Android, macOS, and Linux. No known exploits have been reported, but the potential impact is significant, as Unity is used in a vast number of games and applications. Microsoft and Valve have implemented mitigations, and Unity has released patches and a binary patching tool for developers.
Recommendations Update to the latest patched Unity Editor and rebuild applications to address the vulnerability. If rebuilding is not feasible, use the Unity binary patching tool to patch existing builds. Ensure automatic updates are enabled for games and applications. Keep antivirus software up to date.

Exploit

Fix

RCE

LPE

Argument Injection

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2025-13636
CVE-2025-59489

Affected Products

Unity Runtime