CVE-2025-59489
HIGHDescription
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.
Is your site exposed to CVE-2025-59489?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| unity | editor |
| apple | macos |
| android | |
| linux | linux_kernel |
| microsoft | windows |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-59489? +
How severe is CVE-2025-59489? +
What products are affected by CVE-2025-59489? +
How do I check if I'm vulnerable to CVE-2025-59489? +
Related Vulnerabilities
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects …
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses …
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate …
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by …
XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command …