CVE-2025-59489

Published Oct 3, 2025

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-59489 is a vulnerability in the Unity Runtime that affects games and applications built on Unity. Discovered on June 4, 2025, the vulnerability exists in Unity versions 2017.1 and later. It stems from the intent handling process, which allows malicious intents to control command line arguments passed to Unity applications. This could allow attackers to load arbitrary shared libraries and execute malicious code. The vulnerability involves an untrusted search path, potentially leading to unsafe file loading and local file inclusion. Exploitation could result in local code execution or information disclosure at the privilege level of the vulnerable application. The vulnerability primarily affects applications running on Android, Windows, Linux, and macOS. Unity has released patches for Unity 2019.1 and later, as well as a Unity Binary Patch tool to address the issue.

Description
Unity Editor 2019.1 through 6000.3 could allow remote attackers to exploit file loading and Local File Inclusion (LFI) mechanisms via a crafted local application because of an Untrusted Search Path. This could permit unauthorized manipulation of runtime resources and third-party integrations. The issue could affect applications built using Unity and deployed across Android, Windows, macOS, and Linux platforms.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
5.9
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-426

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

41

  1. We have been working to address the recently disclosed Unity security vulnerability(CVE-2025-59489), and mitigation for the games we published on Steam is nearly complete. Details in thread. 🧵👇 https://t.co/O6a6gNwsXk

    @PsychoFlux_ent

    5 Oct 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CRITICAL ALERT: Unity Flaw (CVE-2025-59489) Exposes Nearly A Decade of Games to Arbitrary Code Execution. Read the full report on - https://t.co/zQzmnDYD9C https://t.co/MgKgWzUb0r

    @Iambivash007

    5 Oct 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Added mitigations for Unity CVE-2025-59489, blocking a game launch through the Steam Client when an exploit attempt is detected. のところ https://t.co/VzFxIVbxVz

    @kumakochocolate

    5 Oct 2025

    129 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 旧バージョンUnityでビルド時に脆弱性パッチを自動で当てるやつ(CVE-2025-59489) https://t.co/PCMCjS8NHe #Qiita @FizDvより

    @yousukezan

    5 Oct 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 新着Unity記事! 『旧バージョンUnityでビルド時に脆弱性パッチを自動で当てるやつ(CVE-2025-59489)』 by -Fiz- #Unity #Qiita https://t.co/i7OmQkHviZ

    @UnityTweetBot

    4 Oct 2025

    150 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 【オタクへ】 プニヒローダー2にCVE-2025-59489に対応するパッチを適用しました。最新のビルドIDは20254869です。Steamクライアントを自動アップデートさせておけば問題なさそうですが念のため… https://t.co/rhH43aOrNq

    @KaninoYokonobu

    4 Oct 2025

    606 Impressions

    4 Retweets

    11 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 🛡️ Cyber Threat Digest – 2025-10-04 KEV: CVE-2014-6278 — GNU Bash OS Command NVD: CVE-2025-59489 — Unity Runtime before 2025-10-02 News: Hackers steal identifiable Discord user data… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    4 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-59489、普通にRCEなのか。やめてよぉ~

    @abdda149

    4 Oct 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Unityの古いバージョン(2017.1以降)で発見されたセキュリティ脆弱性(CVE-2025-59489)で、攻撃者がユーザーのPCをリモートで悪用する可能性だと!?🙄Steamで配信されたUnity制ゲーム怖くて買えない🥺Steamは大手の

    @monjirou1989X

    4 Oct 2025

    219 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Steam Clientアプデに脆弱性修正かー >Added mitigations for Unity CVE-2025-59489, blocking a game launch through the Steam Client when an exploit attempt is detected.

    @kuroganet39

    4 Oct 2025

    242 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Enigmatic Networkの全ゲームについて、Unityランタイムの脆弱性CVE-2025-59489への対処を(一応)行いました。

    @nokoyama_en

    4 Oct 2025

    698 Impressions

    0 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. We're pleased to announce that all of our downloadable game builds have been patched to fix the CVE-2025-59489 vulnerability of the Unity Editor, on Steam and Itch, for our two games: ➡️ Escape Space ➡️ Robot Arena Survivors Thank you for your trust, and have fun!

    @shidygames

    4 Oct 2025

    91 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. I decided to delist the OG game from itch today since I read up on the CVE-2025-59489 Unity issue. Decided way too much of a hassle to patch the old game since it was already difficult to package it since it was very shoddy. And I haven't used Unity for like over 3 year now too.

    @CRUMVIII

    4 Oct 2025

    556 Impressions

    2 Retweets

    12 Likes

    1 Bookmark

    4 Replies

    0 Quotes

  14. The Unity Security bug (affecting all Unity games) has been patched in Pinnacle Point and uploaded to Steam. CVE-2025-59489 related. #gamedev #screenshotsaturday #indiegames #horrorgames https://t.co/zpGXtRG52M

    @Ready2RunGames

    4 Oct 2025

    639 Impressions

    0 Retweets

    24 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. CVE-2025-59489: Arbitrary Code Execution in Unity Runtime - GMO Flatt Security Research - https://t.co/0jG5KvvnGt

    @piedpiper1616

    4 Oct 2025

    1735 Impressions

    5 Retweets

    25 Likes

    11 Bookmarks

    1 Reply

    0 Quotes

  16. 🚨 Critical Unity flaw (CVE-2025-59489) exposes 70% of mobile games to code execution attacks. Affects titles like Among Us & Pokémon GO. ✅ Update your games NOW ✅ Devs: rebuild with patched Unity Editor No exploitation yet, but patches are urgent. Read Details- https:

    @cyberkendra

    4 Oct 2025

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Security update (Oct 3, 2025) Unity disclosed a vulnerability in the Unity engine (CVE-2025-59489). This is not caused by our code or infrastructure—it originates upstream in the Unity platform. What’s affected in our catalog Windows (PC) versions in the Xbox/Microsoft Stor

    @Webnetic2

    4 Oct 2025

    683 Impressions

    3 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2025-59489 MITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability https://t.co/xUX12C1G2l #SecQube #cybersecurity

    @SecQube

    4 Oct 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. このUnityのCVE-2025-59489はまだCVSSのスコアはついてないのかな

    @_0xal1s_

    4 Oct 2025

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2025-59489対応

    @yoggy

    4 Oct 2025

    117 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 開發者注意:Unity 發現高危漏洞 CVE-2025-59489(影響 Unity 2017.1+ → Windows/Android/macOS/Linux)。 請立即 更新 Editor 並重新 build,若短期無法重建可暫用 Unity Binary Patcher。 詳情影片 → https://t.co/o6qaX0TZZp #Unity #GameDev #資

    @MonkeyTree_Ron

    4 Oct 2025

    153 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  22. PSA: Unity CVE-2025-59489 doesn't affect RCADIA @RCADIAHQ users: You're safe. ✅ The vulnerability affects Android/Windows/macOS/Linux builds—NOT WebGL. This is exactly why we built on browser-native WebGL: sandboxed security, no native library exploits, no command-line htt

    @ShaneOnChain

    4 Oct 2025

    367 Impressions

    1 Retweet

    9 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Lỗ hổng CVE-2025-59489 cho phép một app độc hại trên cùng thiết bị buộc app dựng bằng Unity (rủi ro cao với game và ứng dụng ví tiền số) tải và chạy mã gốc với quyền của app đó, nên cập nhật Unity/bản vá ngay, tránh c

    @Let_invest9925

    3 Oct 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Unity just sent out an email telling everyone who released a game between 2017 and today that they need to recompile and republish their games due to a security vulnerability. Yikes. CVE-2025-59489 https://t.co/uXgGFMsvFV

    @gdeglin

    3 Oct 2025

    638 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  25. Unity 2017.1以降の広いプラットフォームに影響する脆弱性 (CVE-2025-59489)、中々影響範囲ヤバそう ゲームアプリケーションって実質的にアップデートが放棄されてるような物も少なくないだろうしなあ https://t.co/M

    @hogehoge61

    3 Oct 2025

    393 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Notice for Unity Game Developers: CVE-2025-59489 https://t.co/WP8V68FrhK

    @SteamDB

    3 Oct 2025

    31203 Impressions

    42 Retweets

    298 Likes

    31 Bookmarks

    7 Replies

    6 Quotes

  27. Unity の脆弱性 CVE-2025-59489 アシュテもUnity を使ってる認識だけど、 影響どうなんだろう。 修正パッチ等出るんかな。 https://t.co/o4PQ8Grmpg

    @Doraemon_Ashta

    3 Oct 2025

    729 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. #Unity just revealed a critical flaw (CVE-2025-59489) that’s been lurking since 2017. What it means, why it matters, and how to fix it, explained simply. Read here 👉 https://t.co/XiglXOpx5S

    @GuardingPearSof

    3 Oct 2025

    66 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. CVE-2025-59489 - CVSS Score: 8.4 Update your Unity3D Editor or patch the game binary 😀 https://t.co/hD6YZxe7tn

    @StudioSG

    3 Oct 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  30. CVE-2025-59489 Unity Editor 2019.1 through 6000.3 could allow remote attackers to exploit file loading and Local File Inclusion (LFI) mechanisms via a crafted local application beca… https://t.co/L8fIYm74PO

    @CVEnew

    3 Oct 2025

    198 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Unity Editor Hit by CVE-2025-59489 There's an untrusted search path and LFI vulnerability in Unity Editor. Attackers can load malicious files or read sensitive info. Patch ASAP. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec https://t.co/e3cS2eYFgX

    @ZeroPathLabs

    3 Oct 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 機能発表されたUnity に関する脆弱性CVE-2025-59489だけど、これ対象範囲広すぎるし、VRChatみたいなそれぞれがビルドしてアップロードする形を取るやつだと前にあったLog4jみたいに結構大きな騒動になりそうだけ

    @My_MC256

    3 Oct 2025

    342 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  33. ❗️방금전에 유니티(Unity)에서 이메일 왔네요! ❗️ 안드로이드 기반 모바일 게임에 서드파티 코드가 실행될 수 있는 문제가 있다는데 이용자의 크립토 지갑까지 위협할 수 있는 취약점이라 크립토 지갑은 꼭 안

    @tshse2

    3 Oct 2025

    150 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 刚刚收到Unity连发的四封邮件,Unity 公布了一个严重漏洞(CVE-2025-59489),影响所有 2017.1 及之后版本 的构建。 目前没有发现被利用的证据,但 官方补丁已发布。 开发者请立刻更新 Unity 版本、重新打包并发布应

    @DLKFZWilliam2

    3 Oct 2025

    1047 Impressions

    0 Retweets

    11 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  35. CVE-2025-59489: Arbitrary Code Execution in Unity Runtime https://t.co/6Nxm1sTiiU https://t.co/8pBEJTSf3J

    @secharvesterx

    3 Oct 2025

    296 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. セキュリティリサーチャーのRyotaK @ryotkak がUnityランタイムにおける任意コード実行の脆弱性を発見しました(CVE-2025-59489)。 この脆弱性の影響を受ける場合、バージョンアップデートを行いアプリケーションを

    @flatt_security

    3 Oct 2025

    3372 Impressions

    10 Retweets

    20 Likes

    9 Bookmarks

    0 Replies

    2 Quotes

  37. Our researcher RyotaK @ryotkak found an Arbitrary Code Execution vulnerability in the Unity Runtime (CVE-2025-59489). We urge all Unity developers to download updated versions, recompile their projects, and republish immediately. https://t.co/uA8dSJFoN6

    @flatt_sec_en

    3 Oct 2025

    9449 Impressions

    22 Retweets

    47 Likes

    10 Bookmarks

    0 Replies

    6 Quotes