← Back

CVE-2025-59489

nvd nist
Published: Oct 3, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

Affected (23)

Products: Unity: Editor
1 product
Editor
Configuration A
23 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Unity
From 2017.4 to 2018.4
From 2019.1 to 2019.1.15f1
From 2019.2 to 2019.2.23f1
From 2019.3 to 2019.3.17f1
From 2020.1 to 2020.1.18f1
From 2020.2 to 2020.2.8f1
From 2020.3 to 2020.3.49f1
From 2021.1 to 2021.1.29f1
From 2021.2 to 2021.2.20f1
From 2022.1 to 2022.1.25f1
From 2022.2 to 2022.2.23f1
From 6000.1 to 6000.1.17f1
From 6000.2 to 6000.2.6f2
From 6000.3 to 6000.3.0b4
From 2019.4 to 2019.4.41f1
From 2021.3 to 2021.3.45f2
From 2022.3 to 2022.3.62f2
From 2023.1 to 2023.1.22f1
From 2023.2 to 2023.2.22f1
From 6000.0 to 6000.0.58f2
Version 2017.1.2p4+
Version 2017.2.0p4+
Version 2017.3.0b9+
Running on/withPlatform Versions
Apple
Macos
All versions
Google
Android
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (3)

Timeline

No history available yet.