Unity Technologies has issued a critical security advisory, warning developers of a high-severity vulnerability affecting its widely used game development platform.
See also: Critical vulnerabilities in the TOTOLINK X6000R Router

The vulnerability, codenamed CVE-2025-59489, exposes applications built with vulnerable versions of the Unity Editor to insecure file loading attacks, which could allow local code execution and privilege escalation across multiple operating systems.
The vulnerability results from an untrusted search path vulnerability (CWE-426) that allows attackers to exploit insecure file loading mechanisms within applications built with Unity.
With a CVSS score of 8.4, this security issue affects nearly all versions of Unity Editor from version 2017.1 to current versions, potentially impacting millions of developed games and applications worldwide.
The vulnerability manifests itself differently depending on the operating system, with Android applications facing the highest risk as they are vulnerable to both code execution and privilege escalation attacks.
Windows, Linux Desktop, Linux Embedded , and macOS platforms face privilege escalation vulnerabilities, allowing attackers to gain unauthorized access to the application's privilege level.
Security researchers at GMO Flatt Security Inc. discovered the vulnerability on June 4, 2025, through responsible disclosure practices.
See also: Bug in Microsoft Defender for Endpoint causes false BIOS alerts

The vulnerability exploits local file inclusion mechanisms, allowing attackers to execute arbitrary code limited to the privilege level of the vulnerable application, while potentially gaining access to confidential information available in this process.
On Windows systems, the threat landscape becomes more complex when custom URI handlers are registered for Unity applications. Attackers who can enable these URI schemes could exploit vulnerable library loading behavior without requiring direct command-line access, significantly expanding the attack surface.
Unity has released updates for all supported versions and has extended fixes to older versions dating back to Unity 2019.1.
The company provides two main remediation approaches: rebuilding applications with updated versions of the Unity Editor or applying binary updates using Unity's specialized update tool for developed applications.
Current supported versions, including 6000.3, 6000.2, 6000.0 LTS, 2022.3 xLTS , and 2021.3 xLTS, have received immediate updates.
Older versions spanning 2019.1 to 2023.2 also received security updates, although versions 2017.1 to 2018.4 remain unpatched and should be upgraded immediately.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: PoC released for critical vulnerability in VMware Workstation

The vulnerability vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates local attack vectors with low complexity requirements and no need for user interaction, making exploitation relatively simple for attackers with local access to the system.
