CVE-2025-59489 PUBLISHED

Assigner: mitre
Reserved: 16.09.2025 Published: 03.10.2025 Updated: 03.10.2025

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.4

Product Status

Vendor Unity3D
Product Unity Editor
Versions Default: unaffected
  • affected from 6000.3 to 6000.3.0b4 (excl.)
  • affected from 6000.2 to 6000.2.6f2 (excl.)
  • affected from 6000.0 LTS to 6000.0.58f2 (excl.)
  • affected from 2022.3 xLTS to 2022.3.67f2 (excl.)
  • affected from 2021.3 xLTS to 2021.3.56f2 (excl.)
  • affected from 6000.1 to 6000.1.17f1 (excl.)
  • affected from 2023.2 to 2023.2.22f1 (excl.)
  • affected from 2023.1 to 2023.1.22f1 (excl.)
  • affected from 2022.3 LTS to 2022.3.62f2 (excl.)
  • affected from 2022.2 to 2022.2.23f1 (excl.)
  • affected from 2022.1 to 2022.1.25f1 (excl.)
  • affected from 2021.3 LTS to 2021.3.45f2 (excl.)
  • affected from 2021.2 to 2021.2.20f1 (excl.)
  • affected from 2021.1 to 2021.1.29f1 (excl.)
  • affected from 2020.3 to 2020.3.49f1 (excl.)
  • affected from 2020.2 to 2020.2.8f1 (excl.)
  • affected from 2020.1 to 2020.1.18f1 (excl.)
  • affected from 2019.4 LTS to 2019.4.41f1 (excl.)
  • affected from 2019.3 to 2019.3.17f1 (excl.)
  • affected from 2019.2 to 2019.2.23f1 (excl.)
  • affected from 2017.1.2p4 to 2019.1.15f1 (excl.)

References

Problem Types

  • CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') CWE