Particle.news

Download on the App Store

Unity Urges Immediate Updates After High-Severity Flaw in Games Built Since 2017

The flaw enables unsafe file loading that could escalate to local code execution.

Overview

  • Unity says projects built with Unity 2017.1 or later on Windows, Android, macOS, and Linux may contain the vulnerability, which carries a CVSS score of 8.4.
  • A fix was issued on October 2, and Unity is telling developers to recompile and republish or use its application patcher for Android, Windows, and macOS.
  • The patcher does not support Linux and may fail on builds protected by anti-cheat or tamper-proofing, so some titles will require full rebuilds.
  • Platform mitigations are live, including a new Steam release with protections, updated Microsoft Defender detections, and additional steps by Google and Meta.
  • Unity reports no evidence of exploitation, and there are no findings to suggest impact on iOS, visionOS, tvOS, Xbox, Nintendo Switch, PlayStation, UWP, Quest, or WebGL.