Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59489

32
FAUCET Score

CVE-2025-59489 is a high-severity argument injection vulnerability affecting Unity Runtime on Android, Windows, macOS, and Linux, allowing attackers to load malicious library code from unintended locations. This flaw can lead to arbitrary code execution and data exfiltration from applications built with vulnerable Unity Editor versions. With a CVSS score of 8.4, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered substantial community discussion and media coverage, indicating high awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2017.1.2p4, < 2019.1.15f1CPE match
cpe:2.3:a:unity3d:unity_editor:*:*:*:*:*:*:*:*
>= 2019.2, < 2019.2.23f1CPE match
cpe:2.3:a:unity3d:unity_editor:*:*:*:*:*:*:*:*
>= 2019.3, < 2019.3.17f1CPE match
cpe:2.3:a:unity3d:unity_editor:*:*:*:*:*:*:*:*
>= 2020.1, < 2020.1.18f1CPE match
cpe:2.3:a:unity3d:unity_editor:*:*:*:*:*:*:*:*
>= 2020.2, < 2020.2.8f1CPE match
cpe:2.3:a:unity3d:unity_editor:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 66th percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Mesh for Meta QuestFixed in: 5.2514
View patch
microsoftpatch availablevia msrc
Product: Microsoft Mesh PC ApplicationsFixed in: 5.2514
View patch

Vendor Advisories (1)

microsoft2025-Oct/CVE-2025-59489Important

MITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability

Oct 14, 2025

References

flatt.tech / research/posts/arbitrary-code-execution-in-unity-runtime
ExploitThird Party Advisory
unity.com / security
Product
unity.com / security/sept-2025-01
Vendor Advisory