CVE Database
/

CVE-2025-59489

Back to search

CVE-2025-59489

Published: Oct 3, 2025

Modified: Oct 3, 2025

PUBLISHED

CVSS v3.1

7.4

HIGH

Description

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

VendorProductVersions

Unity3D

Unity Editor

affected
6000.3 - < 6000.3.0b4
affected
6000.2 - < 6000.2.6f2
affected
6000.0 LTS - < 6000.0.58f2
affected
2022.3 xLTS - < 2022.3.67f2
affected
2021.3 xLTS - < 2021.3.56f2

+16 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now