AI description
CVE-2025-59489 is a vulnerability in the Unity Runtime that affects games and applications built on Unity. Discovered on June 4, 2025, the vulnerability exists in Unity versions 2017.1 and later. It stems from the intent handling process, which allows malicious intents to control command line arguments passed to Unity applications. This could allow attackers to load arbitrary shared libraries and execute malicious code. The vulnerability involves an untrusted search path, potentially leading to unsafe file loading and local file inclusion. Exploitation could result in local code execution or information disclosure at the privilege level of the vulnerable application. The vulnerability primarily affects applications running on Android, Windows, Linux, and macOS. Unity has released patches for Unity 2019.1 and later, as well as a Unity Binary Patch tool to address the issue.
- Description
- Unity Editor 2019.1 through 6000.3 could allow remote attackers to exploit file loading and Local File Inclusion (LFI) mechanisms via a crafted local application because of an Untrusted Search Path. This could permit unauthorized manipulation of runtime resources and third-party integrations. The issue could affect applications built using Unity and deployed across Android, Windows, macOS, and Linux platforms.
- Source
- cve@mitre.org
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.4
- Impact score
- 5.9
- Exploitability score
- 2.5
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-426
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
41
We have been working to address the recently disclosed Unity security vulnerability(CVE-2025-59489), and mitigation for the games we published on Steam is nearly complete. Details in thread. 🧵👇 https://t.co/O6a6gNwsXk
@PsychoFlux_ent
5 Oct 2025
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CRITICAL ALERT: Unity Flaw (CVE-2025-59489) Exposes Nearly A Decade of Games to Arbitrary Code Execution. Read the full report on - https://t.co/zQzmnDYD9C https://t.co/MgKgWzUb0r
@Iambivash007
5 Oct 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Added mitigations for Unity CVE-2025-59489, blocking a game launch through the Steam Client when an exploit attempt is detected. のところ https://t.co/VzFxIVbxVz
@kumakochocolate
5 Oct 2025
129 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
旧バージョンUnityでビルド時に脆弱性パッチを自動で当てるやつ(CVE-2025-59489) https://t.co/PCMCjS8NHe #Qiita @FizDvより
@yousukezan
5 Oct 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
新着Unity記事! 『旧バージョンUnityでビルド時に脆弱性パッチを自動で当てるやつ(CVE-2025-59489)』 by -Fiz- #Unity #Qiita https://t.co/i7OmQkHviZ
@UnityTweetBot
4 Oct 2025
150 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【オタクへ】 プニヒローダー2にCVE-2025-59489に対応するパッチを適用しました。最新のビルドIDは20254869です。Steamクライアントを自動アップデートさせておけば問題なさそうですが念のため… https://t.co/rhH43aOrNq
@KaninoYokonobu
4 Oct 2025
606 Impressions
4 Retweets
11 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️ Cyber Threat Digest – 2025-10-04 KEV: CVE-2014-6278 — GNU Bash OS Command NVD: CVE-2025-59489 — Unity Runtime before 2025-10-02 News: Hackers steal identifiable Discord user data… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv
@dpharristech
4 Oct 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-59489、普通にRCEなのか。やめてよぉ~
@abdda149
4 Oct 2025
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Unityの古いバージョン(2017.1以降)で発見されたセキュリティ脆弱性(CVE-2025-59489)で、攻撃者がユーザーのPCをリモートで悪用する可能性だと!?🙄Steamで配信されたUnity制ゲーム怖くて買えない🥺Steamは大手の
@monjirou1989X
4 Oct 2025
219 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Steam Clientアプデに脆弱性修正かー >Added mitigations for Unity CVE-2025-59489, blocking a game launch through the Steam Client when an exploit attempt is detected.
@kuroganet39
4 Oct 2025
242 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Enigmatic Networkの全ゲームについて、Unityランタイムの脆弱性CVE-2025-59489への対処を(一応)行いました。
@nokoyama_en
4 Oct 2025
698 Impressions
0 Retweets
8 Likes
0 Bookmarks
0 Replies
0 Quotes
We're pleased to announce that all of our downloadable game builds have been patched to fix the CVE-2025-59489 vulnerability of the Unity Editor, on Steam and Itch, for our two games: ➡️ Escape Space ➡️ Robot Arena Survivors Thank you for your trust, and have fun!
@shidygames
4 Oct 2025
91 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
I decided to delist the OG game from itch today since I read up on the CVE-2025-59489 Unity issue. Decided way too much of a hassle to patch the old game since it was already difficult to package it since it was very shoddy. And I haven't used Unity for like over 3 year now too.
@CRUMVIII
4 Oct 2025
556 Impressions
2 Retweets
12 Likes
1 Bookmark
4 Replies
0 Quotes
The Unity Security bug (affecting all Unity games) has been patched in Pinnacle Point and uploaded to Steam. CVE-2025-59489 related. #gamedev #screenshotsaturday #indiegames #horrorgames https://t.co/zpGXtRG52M
@Ready2RunGames
4 Oct 2025
639 Impressions
0 Retweets
24 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-59489: Arbitrary Code Execution in Unity Runtime - GMO Flatt Security Research - https://t.co/0jG5KvvnGt
@piedpiper1616
4 Oct 2025
1735 Impressions
5 Retweets
25 Likes
11 Bookmarks
1 Reply
0 Quotes
🚨 Critical Unity flaw (CVE-2025-59489) exposes 70% of mobile games to code execution attacks. Affects titles like Among Us & Pokémon GO. ✅ Update your games NOW ✅ Devs: rebuild with patched Unity Editor No exploitation yet, but patches are urgent. Read Details- https:
@cyberkendra
4 Oct 2025
138 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Security update (Oct 3, 2025) Unity disclosed a vulnerability in the Unity engine (CVE-2025-59489). This is not caused by our code or infrastructure—it originates upstream in the Unity platform. What’s affected in our catalog Windows (PC) versions in the Xbox/Microsoft Stor
@Webnetic2
4 Oct 2025
683 Impressions
3 Retweets
8 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-59489 MITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability https://t.co/xUX12C1G2l #SecQube #cybersecurity
@SecQube
4 Oct 2025
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
このUnityのCVE-2025-59489はまだCVSSのスコアはついてないのかな
@_0xal1s_
4 Oct 2025
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-59489対応
@yoggy
4 Oct 2025
117 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
開發者注意:Unity 發現高危漏洞 CVE-2025-59489(影響 Unity 2017.1+ → Windows/Android/macOS/Linux)。 請立即 更新 Editor 並重新 build,若短期無法重建可暫用 Unity Binary Patcher。 詳情影片 → https://t.co/o6qaX0TZZp #Unity #GameDev #資
@MonkeyTree_Ron
4 Oct 2025
153 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
PSA: Unity CVE-2025-59489 doesn't affect RCADIA @RCADIAHQ users: You're safe. ✅ The vulnerability affects Android/Windows/macOS/Linux builds—NOT WebGL. This is exactly why we built on browser-native WebGL: sandboxed security, no native library exploits, no command-line htt
@ShaneOnChain
4 Oct 2025
367 Impressions
1 Retweet
9 Likes
0 Bookmarks
0 Replies
0 Quotes
Lỗ hổng CVE-2025-59489 cho phép một app độc hại trên cùng thiết bị buộc app dựng bằng Unity (rủi ro cao với game và ứng dụng ví tiền số) tải và chạy mã gốc với quyền của app đó, nên cập nhật Unity/bản vá ngay, tránh c
@Let_invest9925
3 Oct 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Unity just sent out an email telling everyone who released a game between 2017 and today that they need to recompile and republish their games due to a security vulnerability. Yikes. CVE-2025-59489 https://t.co/uXgGFMsvFV
@gdeglin
3 Oct 2025
638 Impressions
0 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
Unity 2017.1以降の広いプラットフォームに影響する脆弱性 (CVE-2025-59489)、中々影響範囲ヤバそう ゲームアプリケーションって実質的にアップデートが放棄されてるような物も少なくないだろうしなあ https://t.co/M
@hogehoge61
3 Oct 2025
393 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Notice for Unity Game Developers: CVE-2025-59489 https://t.co/WP8V68FrhK
@SteamDB
3 Oct 2025
31203 Impressions
42 Retweets
298 Likes
31 Bookmarks
7 Replies
6 Quotes
Unity の脆弱性 CVE-2025-59489 アシュテもUnity を使ってる認識だけど、 影響どうなんだろう。 修正パッチ等出るんかな。 https://t.co/o4PQ8Grmpg
@Doraemon_Ashta
3 Oct 2025
729 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
#Unity just revealed a critical flaw (CVE-2025-59489) that’s been lurking since 2017. What it means, why it matters, and how to fix it, explained simply. Read here 👉 https://t.co/XiglXOpx5S
@GuardingPearSof
3 Oct 2025
66 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-59489 - CVSS Score: 8.4 Update your Unity3D Editor or patch the game binary 😀 https://t.co/hD6YZxe7tn
@StudioSG
3 Oct 2025
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-59489 Unity Editor 2019.1 through 6000.3 could allow remote attackers to exploit file loading and Local File Inclusion (LFI) mechanisms via a crafted local application beca… https://t.co/L8fIYm74PO
@CVEnew
3 Oct 2025
198 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Unity Editor Hit by CVE-2025-59489 There's an untrusted search path and LFI vulnerability in Unity Editor. Attackers can load malicious files or read sensitive info. Patch ASAP. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec https://t.co/e3cS2eYFgX
@ZeroPathLabs
3 Oct 2025
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
機能発表されたUnity に関する脆弱性CVE-2025-59489だけど、これ対象範囲広すぎるし、VRChatみたいなそれぞれがビルドしてアップロードする形を取るやつだと前にあったLog4jみたいに結構大きな騒動になりそうだけ
@My_MC256
3 Oct 2025
342 Impressions
0 Retweets
3 Likes
0 Bookmarks
1 Reply
0 Quotes
❗️방금전에 유니티(Unity)에서 이메일 왔네요! ❗️ 안드로이드 기반 모바일 게임에 서드파티 코드가 실행될 수 있는 문제가 있다는데 이용자의 크립토 지갑까지 위협할 수 있는 취약점이라 크립토 지갑은 꼭 안
@tshse2
3 Oct 2025
150 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
刚刚收到Unity连发的四封邮件,Unity 公布了一个严重漏洞(CVE-2025-59489),影响所有 2017.1 及之后版本 的构建。 目前没有发现被利用的证据,但 官方补丁已发布。 开发者请立刻更新 Unity 版本、重新打包并发布应
@DLKFZWilliam2
3 Oct 2025
1047 Impressions
0 Retweets
11 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-59489: Arbitrary Code Execution in Unity Runtime https://t.co/6Nxm1sTiiU https://t.co/8pBEJTSf3J
@secharvesterx
3 Oct 2025
296 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
セキュリティリサーチャーのRyotaK @ryotkak がUnityランタイムにおける任意コード実行の脆弱性を発見しました(CVE-2025-59489)。 この脆弱性の影響を受ける場合、バージョンアップデートを行いアプリケーションを
@flatt_security
3 Oct 2025
3372 Impressions
10 Retweets
20 Likes
9 Bookmarks
0 Replies
2 Quotes
Our researcher RyotaK @ryotkak found an Arbitrary Code Execution vulnerability in the Unity Runtime (CVE-2025-59489). We urge all Unity developers to download updated versions, recompile their projects, and republish immediately. https://t.co/uA8dSJFoN6
@flatt_sec_en
3 Oct 2025
9449 Impressions
22 Retweets
47 Likes
10 Bookmarks
0 Replies
6 Quotes