Mohammedia – Unity Technologies announced on October 2, 2025, that it has released patches for a long-standing security vulnerability, tracked as CVE-2025-59489, affecting games and applications built with Unity 2017.1 and later.
Unity says the flaw stems from an “untrusted search path” issue that lets an attacker influence how and where the game loads code. The bug was responsibly disclosed by researcher RyotaK of GMO Flatt Security Inc.
The vulnerability allows an attacker — especially one with a malicious app installed on the same Android device — to send specially crafted commands (via Android intents) to a Unity game. Those commands could force the game to load a malicious shared library (.so file), executing code with the game’s privileges.
Because many games request broad permissions (file access, network, etc.), such an exploit could let the attacker read data or interact with other apps, including crypto wallets on the device.
Industry response and mitigation steps
To limit damage, Unity provided updated editor builds and a patching tool. Developers are urged to recompile their projects with patched Unity versions or use the Unity Application Patcher for apps they can’t rebuild from source. Unity’s advisory emphasizes there is no evidence that this vulnerability has been exploited so far.
Platform operators and distributors also took action. Valve (Steam) added protections in its client to detect exploit attempts and block malicious launches.
Microsoft has updated Defender to flag potential attacks. Google and others are coordinating mitigations. Some game publishers have already patched affected titles or temporarily pulled them to apply fixes.
For users, the immediate advice is to update their Android games when patches are available, remove apps they don’t trust, and avoid installing unknown APKs. If they use their device to also run a crypto wallet app, they should use a separate, hardened environment.
This incident is a wake-up call. Such a deep vulnerability in a widely used engine can have a strong ripple effect, threatening parts of the ecosystem (like crypto wallets) that might not be initially linked.
The sharp reaction across platforms suggests that both game makers and security teams take such systemic vulnerabilities seriously.
Read Also: FTX to Repay $1.6 Billion to Creditors as Bankruptcy Case Advances








