Unity has found a security vulnerability that has sat dormant for almost a decade: 'Take immediate action to protect your games & apps'
Though Unity claims there's no evidence of impact 'on users or customers.'
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Any games or applications using Unity will need to be patched, the game engine company says, following the discovery of a new vulnerability.
Unity is urging users to update their software as a new security vulnerability has been spotted in Unity versions 2017.1 and later. It's present across versions for Android, Windows, Linux, and macOS operating systems.
Discovered back on June 4 this year, and patched on October 2, this vulnerability meant that users were "susceptible to an unsafe file loading and local file inclusion attack depending on the operating system." This means someone could enable local code execution or grab information at "the privilege level of the vulnerable application".
It was given a high severity score by Unity and a CVSS score of 8.4. With 10 being the most severe, this vulnerability is quite significant. Unity does clarify that "there is no evidence of any exploitation of the vulnerability nor has there been any impact on users or customers."
Games or applications released using version 2017.1 or later may contain this vulnerability, and creators are encouraged to download the patched update of Unity via the Unity Hub or Unity Download Archive.
Unity Version 2017.1, as the name implies, launched all the way back in 2017, so this exploit has been there for eight years now.
If you have developed a game or app using version 2017.1 onwards, Unity 'strongly' recommends you "recompile and republish your application." If your app is on Android, its built-in malware scanning and security features will pick up on affected software, and Windows' Microsoft Defender has also been updated to "detect and block the vulnerability." Valve is also adding additional protections against the vulnerability.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
If you would prefer not to rebuild projects, Unity has published a tool that patches applications on Android, Windows, and macOS. However, this tool does not work on builds with tamper-proofing or anti-cheat measures, and it doesn't work with Linux either.
Linux still has a high severity on the affected platforms table on Unity's website, but Unity clarifies, "Due to the lower risk profile, Unity has not released a Linux version of the Unity Application Patcher. If desired, particularly in environments with strict access control policies, rebuild your Linux application with a patched Unity Editor to remove the vulnerable code paths."
Unity also clarifies "the fix is unlikely to break most games", which sounds less reassuring than might have been intended.
Developers using Unity are being encouraged to inform users to keep devices and applications up to date, as those working off old versions could be vulnerable. It's just good form to make sure software is up-to-date, but it will be particularly important for Unity software going forward.

1. Best gaming laptop: Razer Blade 16
2. Best gaming PC: HP Omen 35L
3. Best handheld gaming PC: Lenovo Legion Go S SteamOS ed.
4. Best mini PC: Minisforum AtomMan G7 PT
5. Best VR headset: Meta Quest 3

James is a more recent PC gaming convert, often admiring graphics cards, cases, and motherboards from afar. It was not until 2019, after just finishing a degree in law and media, that they decided to throw out the last few years of education, build their PC, and start writing about gaming instead. In that time, he has covered the latest doodads, contraptions, and gismos, and loved every second of it. Hey, it’s better than writing case briefs.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.

