Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.
Conclusion & alert: CVE-2025-59489 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.02%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-04 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.4 | 3.1 | HIGH |
|
1.4 | 5.9 | [email protected] |
| 8.4 | 3.1 | HIGH |
|
2.5 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| unity | editor | >= 2017.4, <= 2018.4 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2019.1, < 2019.1.15f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2019.2, < 2019.2.23f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2019.3, <= 2019.3.17f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2019.4, < 2019.4.41f1 | cpe:2.3:a:unity:editor:*:*:*:*:lts:*:*:* |
| unity | editor | >= 2020.1, < 2020.1.18f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2020.2, < 2020.2.8f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2020.3, < 2020.3.49f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2021.1, < 2021.1.29f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2021.2, < 2021.2.20f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2021.3, < 2021.3.45f2 | cpe:2.3:a:unity:editor:*:*:*:*:lts:*:*:* |
| unity | editor | >= 2022.1, < 2022.1.25f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2022.2, < 2022.2.23f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 2022.3, < 2022.3.62f2 | cpe:2.3:a:unity:editor:*:*:*:*:lts:*:*:* |
| unity | editor | >= 2023.1, < 2023.1.22f1 | cpe:2.3:a:unity:editor:*:*:*:*:lts:*:*:* |
| unity | editor | >= 2023.2, < 2023.2.22f1 | cpe:2.3:a:unity:editor:*:*:*:*:lts:*:*:* |
| unity | editor | >= 6000.0, < 6000.0.58f2 | cpe:2.3:a:unity:editor:*:*:*:*:lts:*:*:* |
| unity | editor | >= 6000.1, < 6000.1.17f1 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 6000.2, < 6000.2.6f2 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | >= 6000.3, < 6000.3.0b4 | cpe:2.3:a:unity:editor:*:*:*:*:-:*:*:* |
| unity | editor | 2017.1.2p4\+ | cpe:2.3:a:unity:editor:2017.1.2p4\+:*:*:*:-:*:*:* |
| unity | editor | 2017.2.0p4\+ | cpe:2.3:a:unity:editor:2017.2.0p4\+:*:*:*:-:*:*:* |
| unity | editor | 2017.3.0b9\+ | cpe:2.3:a:unity:editor:2017.3.0b9\+:*:*:*:-:*:*:* |
| URL | Tags |
|---|---|
| https://flatt.tech/research/posts/arbitrary-code-execution-in-unity-runtime/ | Exploit Third Party Advisory |
| https://unity.com/security#security-updates-and-patches | Product |
| https://unity.com/security/sept-2025-01 | Vendor Advisory |