Unity's vulnerability profile centers on its game development platform, covering the editor, runtime components, and web-player delivery mechanism, with observed exposures clustering around information disclosure, argument injection, race conditions, and unsafe search-path handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unity over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54424HIGH An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The | Jul 4, 2026 | 8.4 | 37 | NO | NO |
CVE-2025-59489HIGH Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an applic | Oct 3, 2025 | 8.4 | 32 | NO | NO |
CVE-2023-37250HIGH Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally lau | Aug 20, 2023 | 7.0 | 22 | NO | NO |
CVE-2015-9288MEDIUM The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials | Jul 29, 2019 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unity.
Media articles that mention a CVE ID that affects a product developed by Unity — matched by CVE ID, not by vendor name.