IT

Tracker / CVE-2025-59489

CVE-2025-59489

High 7.4

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

Affected products and versions

unity editor
unity editor · 2017.4 → 2018.4
unity editor · 2019.1 → 2019.1.15f1
unity editor · 2019.2 → 2019.2.23f1
unity editor · 2019.3 → 2019.3.17f1
unity editor · 2019.4 → 2019.4.41f1
unity editor · 2020.1 → 2020.1.18f1
unity editor · 2020.2 → 2020.2.8f1
unity editor · 2020.3 → 2020.3.49f1
unity editor · 2021.1 → 2021.1.29f1
unity editor · 2021.2 → 2021.2.20f1
unity editor · 2021.3 → 2021.3.45f2
unity editor · 2022.1 → 2022.1.25f1
unity editor · 2022.2 → 2022.2.23f1
unity editor · 2022.3 → 2022.3.62f2
unity editor · 2023.1 → 2023.1.22f1
unity editor · 2023.2 → 2023.2.22f1
unity editor · 6000.0 → 6000.0.58f2
unity editor · 6000.1 → 6000.1.17f1
unity editor · 6000.2 → 6000.2.6f2
unity editor · 6000.3 → 6000.3.0b4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References