A vulnerability in Unity Web Playercan be exploited by attackers to retrieve personal messages received by users via Gmail or Facebook, as well as gain access to and read data from the victim's hard drive.
Available as a browser plugin, Unity Web Player is used to render 3D content in games created using Unity cross-platform. The plugin is available for Windows (Internet Explorer, Firefox, Chrome, Safari, Opera), as well as OS X (Firefox, Chrome, Safari). The number of users worldwide is approximately 600 million according to the company.
Security researcher Jouko Pynnönen, from Klikki Oy in Finland, found in 2014 that a security flaw in the player could be exploited to bypass cross-domain policy restrictions, thus allowing access to content from a different domain than the original one.
Pynnönen explains that retrieving content from a different domain can be done by using a malicious Unity app, from the crooks' domain, requesting content from a different source.
If the app requests an allowed URL that redirects to a targeted address like Facebook or Gmail, the browser then loads the resource and logs in using the user's stored credentials. To achieve this, the redirect must contain a configured location header like: https://attacker.site:80@target.site/.
“The URL refers to ‘target.site’, so browser redirection should not be allowed. However, the Unity Web Player plugin will allow browser redirection, due to the user’s credentials,” the researcher explains, adding that the risk is much greater in Internet Explorer, because the attacker could also gain access to local files.
Pynnönen has been sending his report to the company since December 2014 and after many attempts the company responded this month, on June 3rd, that it would soon release a fix to correct the problem.

