Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Megan Fox
Megan Fox
@glassbottommeg@mastodon.gamedev.place  ·  activity timestamp 4 months ago

Couldn't figure out how Unity could have a global security risk, because it's just a stand-alone app etc they don't work like that, and there were two options:

1.) The connection that Unity forces to mothership for analytics (thank gods that wasn't it)

2.) Do you rely on arbitrary code exec? Mods? Oops. #GameDev #Unity3D

Overview

A critical security vulnerability has been identified affecting games and applications built with Unity 2017.1 and later for Android, Windows, and macOS. This vulnerability may allow malicious actors with local access to execute arbitrary code within your application’s context, potentially leading to data exposure or privilege escalation.

This vulnerability originates from command-line arguments that allow Unity applications to load and execute arbitrary code. The impact of this vulnerability varies across host platforms. To understand how the vulnerability affects your target platforms, refer to Platform-specific technical notes.

Important: If your project was built with any Unity version from 2017 up to today’s patched releases, it may be affected. All developers with affected projects must take action.
Overview A critical security vulnerability has been identified affecting games and applications built with Unity 2017.1 and later for Android, Windows, and macOS. This vulnerability may allow malicious actors with local access to execute arbitrary code within your application’s context, potentially leading to data exposure or privilege escalation. This vulnerability originates from command-line arguments that allow Unity applications to load and execute arbitrary code. The impact of this vulnerability varies across host platforms. To understand how the vulnerability affects your target platforms, refer to Platform-specific technical notes. Important: If your project was built with any Unity version from 2017 up to today’s patched releases, it may be affected. All developers with affected projects must take action.
Overview A critical security vulnerability has been identified affecting games and applications built with Unity 2017.1 and later for Android, Windows, and macOS. This vulnerability may allow malicious actors with local access to execute arbitrary code within your application’s context, potentially leading to data exposure or privilege escalation. This vulnerability originates from command-line arguments that allow Unity applications to load and execute arbitrary code. The impact of this vulnerability varies across host platforms. To understand how the vulnerability affects your target platforms, refer to Platform-specific technical notes. Important: If your project was built with any Unity version from 2017 up to today’s patched releases, it may be affected. All developers with affected projects must take action.
  • Copy link
  • Flag this post
  • Block
Megan Fox
Megan Fox
@glassbottommeg@mastodon.gamedev.place replied  ·  activity timestamp 4 months ago

Anyways this is the link with more details if you were trying to drill down to "does this matter to me?" https://unity.com/security/sept-2025-01/remediation

Unity

Unity Security Vulnerability: Developer Remediation Guide

A security vulnerability was identified that affects games and applications built on Unity versions 2017.1 and later for Android, Windows, and macOS operating systems. Download the patching tool here and read on for further instructions.
  • Copy link
  • Flag this comment
  • Block
Megan Fox
Megan Fox
@glassbottommeg@mastodon.gamedev.place replied  ·  activity timestamp 4 months ago

Honestly even then, I genuinely don't get why most would care about this.

This is a way of getting elevated access if you are sitting (or e-sitting) at the keyboard, running the executable, adding a command line.

There's uh. There are easier ways of gaining access. Most games are execution sieves.

  • Copy link
  • Flag this comment
  • Block
Megan Fox
Megan Fox
@glassbottommeg@mastodon.gamedev.place replied  ·  activity timestamp 4 months ago

My suspicion is folks are panicking because for a long time now Unity's been an everything-engine. Which was always a bit stupid, cus the needs of say, a back-end intranet management application differ from those of a game, but it made it Easy, so people did it and

THERE, this matters, oh mah gawd.

  • Copy link
  • Flag this comment
  • Block
Megan Fox
Megan Fox
@glassbottommeg@mastodon.gamedev.place replied  ·  activity timestamp 4 months ago

That also scans with why Windows would suddenly care. They don't give a shit if a game punches a hole through Defender, cus (games srsly).

But.

A whole lot of people used a game engine on critical infrastructure.

A game engine capable of arbitrary code execution (which we love for mods). And. Oh.

  • Copy link
  • Flag this comment
  • Block
Megan Fox
Megan Fox
@glassbottommeg@mastodon.gamedev.place replied  ·  activity timestamp 4 months ago

Anyways, remember my "do you REALLY need to be using a port-everywhere game engine" post? https://mastodon.gamedev.place/@glassbottommeg/115300081718370888

Yeahh there's a bunch of other inherent issues with turning a single game engine into a load-bearing pillar of the entire computing world

I wonder if this'll cause backtracking there?

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct