Overview
- Unity says projects built with Unity 2017.1 or later on Windows, Android, macOS, and Linux may contain the vulnerability, which carries a CVSS score of 8.4.
- A fix was issued on October 2, and Unity is telling developers to recompile and republish or use its application patcher for Android, Windows, and macOS.
- The patcher does not support Linux and may fail on builds protected by anti-cheat or tamper-proofing, so some titles will require full rebuilds.
- Platform mitigations are live, including a new Steam release with protections, updated Microsoft Defender detections, and additional steps by Google and Meta.
- Unity reports no evidence of exploitation, and there are no findings to suggest impact on iOS, visionOS, tvOS, Xbox, Nintendo Switch, PlayStation, UWP, Quest, or WebGL.