CVE detail
CVE-2025-59489
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
The total amount of money given to bug bounty hunters by the social media giant has reached $25 million.
newswww.securityweek.comNov 18, 2025, 3:30 PMThe tech giant has rolled out fixes for 173 CVEs, including five critical-severity security defects.
newswww.securityweek.comOct 15, 2025, 4:10 AMThe flaw could lead to local code execution, allowing attackers to access confidential information on devices running Unity-built applications.
newswww.securityweek.comOct 6, 2025, 1:06 PMNo excerpt available.
Vendor Advisoryunity.comOct 3, 2025, 2:15 PMNo excerpt available.
Vendor Advisoryunity.comOct 3, 2025, 2:15 PMNo excerpt available.
Exploitflatt.techOct 3, 2025, 2:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48287CVSS 7.4 · High
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on…
- CVE-2012-2040CVSS 9.3 · Critical
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x bef…
- CVE-2025-30399CVSS 7.5 · High
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2020-7851CVSS 7.8 · High
Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting…
- CVE-2016-1014CVSS 7.3 · High
Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows loc…
- CVE-2026-48357CVSS 6.2 · Medium
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerab…