CVE-2025-59489Patch(apple / android)

MEDIUMCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

5.3/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-88CWE-426

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • editor
  • linux_kernel
  • macos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-31); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Products
androideditorlinux_kernelmacoswindows

4 versions affected across 5 products

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-01-29: 1Mentions · 2026-03-03: 1Mentions · 2026-03-12: 1Mentions · 2026-03-31: 2Mentions · 2026-05-12: 1Mentions · 2026-07-06: 1Mentions · 2026-08-03: 1Mentions · 2026-08-18: 1PoC Mentioned / Linked · 2026-03-31: 2Exploit Tool / Code · 2026-03-31: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-01-29: 1Technical Details · 2026-03-31: 201-2903-0303-1203-3105-1207-0608-0308-18
Signal classification4 categories
Patch
555.6%
Disclosure
222.2%
Exploit
111.1%
General
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-291
Patch1
2026-03-031
Patch1
2026-03-121
Patch1
2026-03-312
Disclosure1Exploit1
2026-05-121
General1
2026-07-061
Patch1
2026-08-031
Disclosure1
2026-08-181
Patch1
Full discourse9 posts
  • Kyuppin 🧅🪲@Kyuppin
    Patch

    Lily's Night Off v1.6 update was just released! This update adds a Turkish localization done by the hardworking Yunus Sorgunçay! It also patches Unity Vulnerability CVE-2025-59489. https://store.steampowered.com/news/app/890750/view/536628183572677575 https://t.co/dRhtlTfhMT

    Post summary

    The update announces a patch for CVE-2025-59489, indicating a fix has been released.

    11006081.4K
    7.2K followersView on X
  • Kyuppin 🧅🪲@Kyuppin
    Patch

    Lily's Day Off v5 update was just released on Steam and Itchio (android soon)! This update adds a Turkish localization done by the hardworking Yunus Sorguncay! It also patches Unity Vulnerability CVE-2025-59489. https://store.steampowered.com/news/app/575650/view/678507423258902531 https://t.co/7JDRxBIzbL

    Post summary

    The update announces a patch for Unity Vulnerability CVE-2025-59489, with no exploit or PoC details provided.

    1605981.3K
    7.5K followersView on X
  • さいんす(signs)@signs0302
    Patch

    【アップデート】 VR食事支援ソフト「Ukemochi」v1.20を公開しました ・通信を共有メモリ化して大幅高速化(IPアドレス入力も不要に) ・RTX50シリーズなど新GPUに対応 ・VIVEProモードのバグ修正 ・Unity製アプリの脆弱性(CVE-2025-59489)対策を適用 https://signs.booth.pm/items/1822068 #ukemochi

    Post summary

    The update announces a patch for CVE-2025-59489 in the VR dining support app, with no PoC, exploit code, or indication of ongoing attacks.

    0001101.1K
    893 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2025-59489: Unity Hub macOS DyLib Injection – TCC Bypass https://blog.securelayer7.net/cve-2025-59489-unity-hub-macos-tcc-bypass-dylib-injection/

    Post summary

    A new Unity Hub vulnerability (CVE‑2025‑59489) is disclosed, allowing DyLib injection to bypass macOS TCC controls, as detailed in the referenced blog.

    021431.4K
    157.2K followersView on X
  • reverseame@reverseame
    Patch

    CVE-2025-59489: Arbitrary Code Execution in Unity Runtime #UnityVulnerability #ArbitraryCodeExecution #CVE202559489 #GameSecurity #PatchNow https://flatt.tech/research/posts/arbitrary-code-execution-in-unity-runtime/

    Post summary

    The tweet highlights CVE‑2025‑59489—a Unity Runtime vulnerability allowing arbitrary code execution—and urges readers to apply the available patch, referencing a research article for details.

    11012631
    21.6K followersView on X
  • RiverOceano@RayOceano
    Patch

    @realaoiyu_ @JacksonFeyto yeah they patch the game 2026.1.2, but not the SDK according to unity of CVE-2025-59489 of 2022.3.22f1 this is make open back door for them, and they want you think the sdk was patch but, I did research is not, you believe vrchat side but not unity side https://unity.com/security/sept-2025-01

    Post summary

    The tweet discusses the patch status of Unity’s SDK for CVE‑2025‑59489, noting that while the game was patched, the SDK remains unpatched and therefore vulnerable, but no exploit or PoC is provided.

    10000239
    122 followersView on X
  • ひゅーらー@SinHyular
    Disclosure

    @Unknown_34445 半年くらい前にUnityにセキュリティー上の脆弱性(CVE-2025-59489)が発覚したのでそれ以前に制作したゲームはすべて公開を停止しました。

    Post summary

    The user reports that a Unity security vulnerability (CVE-2025-59489) was discovered about six months ago, prompting them to suspend releases of earlier games.

    0000060
    6.3K followersView on X
  • RiverOceano (Vaporeon)@RayOceano
    General

    @LumiiVRC want me to exposed vrchat back door about 2022.3.2f1 CVE-2025-59489 high risk has nothing do with somnium

    Post summary

    The tweet references CVE-2025-59489 affecting VRChat 2022.3.2f1, labels it as high risk, but offers no technical specifics, proof of concept, or evidence of exploitation.

    000001.4K
    210 followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    Exploit

    https://blog.securelayer7.net/cve-2025-59489-unity-hub-macos-tcc-bypass-dylib-injection/

    Post summary

    The blog presents CVE‑2025‑59489, detailing a TCC bypass in Unity Hub through dylib injection, supplies PoC and exploit code, outlines a patch, but does not report active exploitation.

    00000253
    3.2K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSgoogleandroid---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
Appunityeditor---
Appunityeditor---
Appunityeditor2017.1.2p4\+--
Appunityeditor2017.2.0p4\+--
Appunityeditor2017.3.0b9\+--

Explore more