A critical vulnerability, tracked as CVE-2025-59489, was discovered in the Unity Editor versions 2019.1 through 6000.3, as well as in the Unity Runtime affecting games and applications built on Unity 2017.1 and later. The flaw arises from an untrusted search path issue, which allows attackers to exploit file loading and Local File Inclusion (LFI) mechanisms through a crafted local application. This vulnerability can permit unauthorized manipulation of runtime resources and third-party integrations, potentially leading to arbitrary code execution. The vulnerability was identified by a security engineer during the Meta Bug Bounty Researcher Conference in May 2025 and responsibly disclosed to Unity. Unity responded by releasing patches for Unity 2019.1 and later, along with a Unity Binary Patch tool to help developers remediate the issue. The technical root of the vulnerability lies in Unity’s intent handler, where malicious intents can control command line arguments passed to Unity applications. This enables attackers to load arbitrary files or libraries, which can be leveraged for code execution. Attack scenarios include both local attacks, where a user is tricked into running a malicious application, and remote exploitation via browser under certain conditions. The vulnerability affects applications deployed across multiple platforms, including Android, Windows, macOS, and Linux. SELinux restrictions may mitigate some remote exploitation vectors, but the risk remains significant for unpatched systems. Developers are strongly urged to update to the latest Unity versions, recompile their applications, and republish them to ensure users are protected. The vulnerability does not require remote exploitation by default, but the attack surface is broad due to the widespread use of Unity in the gaming and application development ecosystem. Unity’s official security advisory provides further guidance and details on remediation steps. The prompt response from Unity and the security community highlights the importance of coordinated vulnerability disclosure. This incident underscores the need for ongoing vigilance and timely patching in software supply chains. Organizations using Unity-based applications should assess their exposure and prioritize updates to mitigate the risk of exploitation. The vulnerability’s high CVSS score reflects its potential impact and the urgency of remediation.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Kaspersky published guidance warning about the Unity engine vulnerability and recommending that users update affected games and applications. The advisory reflected continued downstream response after Unity's disclosure.
Major platform and security vendors, including Google, Valve, Meta, and Microsoft, implemented additional mitigations in response to CVE-2025-59489. These steps were taken to reduce exposure while developers updated affected software.
Steam announced it would block launches of games using certain Unity-reported command-line parameters that could be abused in connection with the vulnerability. The change was introduced as a platform-level mitigation.
Microsoft advised users to temporarily uninstall vulnerable Microsoft apps and games built with affected Unity versions until updates became available. The guidance was issued as a mitigation against possible exploitation.
Following Unity's disclosure, Obsidian Entertainment temporarily removed some games from sale while addressing the vulnerability. This reflected early industry response to the risk posed by affected Unity-built titles.
Unity disclosed CVE-2025-59489, warning that software built with Unity Editor 2017.1 and later could be affected on Android, Windows, macOS, and Linux. The company said patched Unity releases and a binary patcher tool were available, and stated there was no evidence of exploitation in the wild.
CVE-2025-59489 was publicly cataloged as a high-severity vulnerability affecting Unity Editor versions including 2019.1 through 6000.3. The listing marked broader public tracking of the issue.
GMO Flatt Security published research describing CVE-2025-59489 as an arbitrary code execution issue in Unity Runtime. The publication provided public technical details about the flaw.
RyotaK of GMO Flatt Security reported the Unity vulnerability later tracked as CVE-2025-59489 at the Meta Bug Bounty Researcher Conference. The report was made in June 2025, initiating coordinated disclosure and remediation efforts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcethecyberexpress.com
Open sourcetherecord.media
Open sourcecvefeed.io
Open sourceflatt.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.