
Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against patched versions, with batch processing and CI/CD integration.
An automated detection tool for Unity Runtime injection vulnerabilities, specifically designed for Android game platforms.
In one sentence: An attacker can gain complete control over affected Unity games/applications, obtaining all permissions granted to the application.
Key Point: On Android, a malicious app can hijack permissions already granted to a Unity application
Key Point: On Windows, if the game registers a custom URI handler, clicking a specially crafted link can trigger the vulnerability
| If the game has this permission | The attacker can |
|---|---|
| 📸 Camera | Secretly record you |
| 🎤 Microphone | Eavesdrop on you |
| 📍 Location | Track you |
| 📱 Contacts | Steal your address book |
| 💾 Storage | Read/delete your files |
| 💰 Payments | Fraudulently use in-game payments |
| 🔐 Account | Steal game accounts |
Good news: Attackers cannot exceed the application's own permission boundaries
Bad news: Many games require extensive permissions (camera, microphone, storage, location, etc.), and attackers can fully exploit these permissions
As an Android game platform operator, the worst consequences:
[Source: Unity official security advisory, GMO Flatt Security technical analysis]
# Only requires Python 3.7+ standard library, no additional dependencies
python3 --version # Verify Python version
# Step 1: Run the tests
python test_demo.py
# Step 2: Check a single APK
python unity_vulnerability_checker.py your_game.apk
# Step 3: Batch check
python unity_vulnerability_checker.py --batch /path/to/apks
# Step 4: View usage examples
python usage_examples.py
from unity_vulnerability_checker import check_unity_vulnerability
# Check a single APK file
result = check_unity_vulnerability("your_game.apk")
# Method 1: Use convenience properties
if result.is_vulnerable:
print(f"⚠️ Application affected! ({result.version})")
print(f"Recommendation: {result.recommendation}")
elif result.is_safe:
print(f"✅ Application is safe")
print(f"Reason: {result.message}")
else:
print(f"❓ Manual review required")
print(f"Reason: {result.message}")
# Method 2: Use the status field
if result.status == "positive":
print(f"Affected: {result.version}")
from unity_vulnerability_checker import batch_check
# Batch scan a directory
results = batch_check("/path/to/apk/folder")
# Filter affected applications
vulnerable_apps = [
(name, result)
for name, result in results.items()
if result.is_vulnerable
]
print(f"Found {len(vulnerable_apps)} affected applications")
for name, result in vulnerable_apps:
print(f" - {name}: {result.version}")
from unity_vulnerability_checker import UnityVulnerabilityChecker
class MyPlatform:
"""Your game platform system"""
def __init__(self):
self.checker = UnityVulnerabilityChecker()
def check_new_upload(self, apk_path: str) -> bool:
"""Check newly uploaded APK, return whether it can be published"""
result = self.checker.check_apk(apk_path)
if result.is_vulnerable:
# Affected - reject publication
self.notify_developer(
f"Your application is affected by the Unity vulnerability\n"
f"Version: {result.version}\n"
f"Recommendation: {result.recommendation}"
)
return False
elif result.is_safe:
# Safe - approve publication
return True
else:
# Cannot determine - manual review
self.queue_manual_review(apk_path, result.message)
return False
def notify_developer(self, message: str):
"""Notify developer (implement your notification logic)"""
pass
def queue_manual_review(self, apk_path: str):
"""Add to manual review queue (implement your logic)"""
pass
The tool returns three types of results:
Output Examples (single-line concise format):
# Affected application
⚠️ This application is affected by CVE-2025-59489 (Unity 2019.2.6f1)
# Safe application (3 cases)
✅ This application is safe - Not a Unity application
✅ This application is safe - Already patched with Unity patcher tool
✅ This application is safe - Patched version (2019.4.41f1)
# Cannot determine
❓ Cannot determine - Unity application but version extraction failed, possibly packed or obfuscated, manual review recommended
⚠️ File too large to process (1500.0MB, limit 1024MB) - modify MAX_APK_SIZE_MB on line 15 of the code to a larger value
.
├── unity_vulnerability_checker.py # Core module
│ ├─ UnityVulnerabilityChecker class - Vulnerability detection core engine
│ ├─ check_unity_vulnerability() - Simplified detection function
│ ├─ batch_check() - Batch detection functionality
│ └─ Complete version parsing and determination logic
│
├── usage_examples.py # Usage examples
│ ├─ Basic usage examples
│ ├─ Batch detection examples
│ ├─ Platform integration examples
│ ├─ Automated response examples
│ └─ Flask API integration examples
│
├── test_demo.py # Test demo
│ ├─ Version number parsing tests
│ ├─ Version extraction tests
│ ├─ Patch determination tests
│ ├─ APK scanning scenario simulations
│ └─ Performance benchmark tests
│
├── test_version_detection.py # Unit tests (33 test cases)
│
├── README.md # Complete documentation (includes quick start guide)
│
└── CLAUDE.md # Development guidelines