A critical security flaw in Unity was discovered after 8 years. It puts players at risk, and now all games need an urgent patch

Unity is a great choice for independent developers and smaller game studios, though it’s also used to create larger, more complex games. A common criticism is that games built with Unity sometimes suffer from performance issues. The software has also faced some controversy – while some point fingers at Unity itself, others blame the developers, and the reality is probably a mix of both. Adding to these concerns is a security vulnerability in Unity that has existed since 2017.

New security patch required for all games built with Unity 2017.1 and later

The developer of Tainted Grail: The Fall of Avalon shared information about a Unity issue on the game’s Discord server today. They had previously released a small update, supplied by Unity, to address this problem.

This vulnerability does not affect consoles

The small update we released two days ago was from Unity and fixes a problem. We advise all players to use only the newest version of the game, and avoid older versions, because the vulnerability is now known and could be taken advantage of.

This generally applies to most Unity games. We advise players to be careful and avoid playing these games until an update is available to fix any issues.

Unity has discovered a significant security vulnerability impacting games and applications built with Unity 2017.1 and newer versions on Android, Windows, macOS, and Linux (consoles are not affected). This issue stems from how the software handles command-line arguments, potentially allowing applications to execute unintended code, which could compromise data or grant unauthorized access. Currently, there’s no evidence that this flaw has been used maliciously, but developers are strongly advised to take action.

Unity’s Security Update Advisory states that the vulnerability was found in June 2025 and fixed on October 2, 2025. This means all games created using the engine require an update. It’s not limited to independent developers; major games such as Genshin Impact, Pokémon GO, and Cities: Skylines 2 were also built with Unity, making this a critical issue.

Read More

2025-10-03 14:33