Unity Flaw CVE-2025-59489 Allows Local Code Execution in Millions of Games
ID: e79d5bbc-f81f-5556-8e4e-8dc79c98a136
STIX ID: report--e79d5bbc-f81f-5556-8e4e-8dc79c98a136
Feed Name: securityonline.info
A critical vulnerability (CVE-2025-59489, CVSS 8.4) in the Unity Runtime lets attackers control command-line arguments via the 'unity' intent extra, enabling local file inclusion and loading of arbitrary .so libraries for code execution or privilege escalation across Android and other platforms; exploitation scenarios include a malicious co-installed app and specially crafted intent URLs, though SELinux and other platform protections reduce many remote risks. Unity has released patches for supported and many out-of-support Editor versions and provides a binary patch tool for legacy builds; developers are urged to update, rebuild, or apply the provided binary fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
