Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2025-59489 — Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against patched versions, with batch processing and CI/CD integration. | Kitploit
Tools/GitHubGitHub/taptap/cve-2025-59489
Android SecurityStatic AnalysisVulnerability ScannersDevSecOpsMobile Security
GitHubtaptap/cve-2025-59489

cve-2025-59489

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against patched versions, with batch processing and CI/CD integration.

View Repository
1524011 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Unity CVE-2025-59489 Vulnerability Detection Tool

An automated detection tool for Unity Runtime injection vulnerabilities, specifically designed for Android game platforms.

Vulnerability Overview

  • CVE ID: CVE-2025-59489
  • CVSS Score: 8.4 (High)
  • Affected Scope: Android applications built with Unity 2017.1 and later versions
  • Official Advisory: https://unity.com/security/sept-2025-01

Detailed Impact Analysis

Maximum Impact (Worst Case)

In one sentence: An attacker can gain complete control over affected Unity games/applications, obtaining all permissions granted to the application.

Android Platform Attack Scenarios

  1. The user has a malicious app A installed on their phone
  2. The user also has an affected Unity game B installed on their phone
  3. Malicious app A can:
    • Impersonate game B to execute arbitrary code
    • Steal all data accessible to game B (save files, account information, photos, contacts, etc.)
    • Use all permissions granted to game B (camera, microphone, location, network, etc.)

Key Point: On Android, a malicious app can hijack permissions already granted to a Unity application

Windows Platform Attack Scenarios

  1. The user clicks a malicious web link
  2. If an affected Unity game is installed on the computer
  3. The attacker can:
    • Remotely trigger the game to load malicious code
    • Execute arbitrary operations with the game's permissions
    • Steal files and data accessible to the game

Key Point: On Windows, if the game registers a custom URI handler, clicking a specially crafted link can trigger the vulnerability

Specific Impact Examples

If the game has this permissionThe attacker can
📸 CameraSecretly record you
🎤 MicrophoneEavesdrop on you
📍 LocationTrack you
📱 ContactsSteal your address book
💾 StorageRead/delete your files
💰 PaymentsFraudulently use in-game payments
🔐 AccountSteal game accounts

Important Limitations

Good news: Attackers cannot exceed the application's own permission boundaries

  • ❌ Cannot obtain root privileges
  • ❌ Cannot access other applications' data (Android sandbox protection)
  • ❌ Can only act under the identity of the compromised application

Bad news: Many games require extensive permissions (camera, microphone, storage, location, etc.), and attackers can fully exploit these permissions

Impact on Game Platforms

As an Android game platform operator, the worst consequences:

  1. User privacy leakage → Platform reputation damage
  2. Large-scale account theft → User churn
  3. Legal liability → Failure to fulfill security review obligations
  4. Financial losses → User claims, regulatory penalties

[Source: Unity official security advisory, GMO Flatt Security technical analysis]

Quick Start

Environment Requirements

# Only requires Python 3.7+ standard library, no additional dependencies
python3 --version  # Verify Python version

Get Started in 5 Minutes

# Step 1: Run the tests
python test_demo.py

# Step 2: Check a single APK
python unity_vulnerability_checker.py your_game.apk

# Step 3: Batch check
python unity_vulnerability_checker.py --batch /path/to/apks

# Step 4: View usage examples
python usage_examples.py

Simplest Usage

from unity_vulnerability_checker import check_unity_vulnerability

# Check a single APK file
result = check_unity_vulnerability("your_game.apk")

# Method 1: Use convenience properties
if result.is_vulnerable:
    print(f"⚠️  Application affected! ({result.version})")
    print(f"Recommendation: {result.recommendation}")
elif result.is_safe:
    print(f"✅ Application is safe")
    print(f"Reason: {result.message}")
else:
    print(f"❓ Manual review required")
    print(f"Reason: {result.message}")

# Method 2: Use the status field
if result.status == "positive":
    print(f"Affected: {result.version}")

Batch Check All APKs in a Directory

from unity_vulnerability_checker import batch_check

# Batch scan a directory
results = batch_check("/path/to/apk/folder")

# Filter affected applications
vulnerable_apps = [
    (name, result) 
    for name, result in results.items() 
    if result.is_vulnerable
]
print(f"Found {len(vulnerable_apps)} affected applications")
for name, result in vulnerable_apps:
    print(f"  - {name}: {result.version}")

Integration into Existing Systems

from unity_vulnerability_checker import UnityVulnerabilityChecker

class MyPlatform:
    """Your game platform system"""

    def __init__(self):
        self.checker = UnityVulnerabilityChecker()

    def check_new_upload(self, apk_path: str) -> bool:
        """Check newly uploaded APK, return whether it can be published"""
        result = self.checker.check_apk(apk_path)

        if result.is_vulnerable:
            # Affected - reject publication
            self.notify_developer(
                f"Your application is affected by the Unity vulnerability\n"
                f"Version: {result.version}\n"
                f"Recommendation: {result.recommendation}"
            )
            return False
        elif result.is_safe:
            # Safe - approve publication
            return True
        else:
            # Cannot determine - manual review
            self.queue_manual_review(apk_path, result.message)
            return False

    def notify_developer(self, message: str):
        """Notify developer (implement your notification logic)"""
        pass

    def queue_manual_review(self, apk_path: str):
        """Add to manual review queue (implement your logic)"""
        pass

Understanding Detection Results

The tool returns three types of results:

  • positive - Confirmed affected (update required)
  • negative - Safe (not Unity or already patched)
  • inconclusive - Cannot determine (manual review required)

Output Examples (single-line concise format):

# Affected application
⚠️  This application is affected by CVE-2025-59489 (Unity 2019.2.6f1)

# Safe application (3 cases)
✅ This application is safe - Not a Unity application
✅ This application is safe - Already patched with Unity patcher tool
✅ This application is safe - Patched version (2019.4.41f1)

# Cannot determine
❓ Cannot determine - Unity application but version extraction failed, possibly packed or obfuscated, manual review recommended
⚠️  File too large to process (1500.0MB, limit 1024MB) - modify MAX_APK_SIZE_MB on line 15 of the code to a larger value

Project File Structure

.
├── unity_vulnerability_checker.py  # Core module
│   ├─ UnityVulnerabilityChecker class - Vulnerability detection core engine
│   ├─ check_unity_vulnerability() - Simplified detection function
│   ├─ batch_check() - Batch detection functionality
│   └─ Complete version parsing and determination logic
│
├── usage_examples.py               # Usage examples
│   ├─ Basic usage examples
│   ├─ Batch detection examples
│   ├─ Platform integration examples
│   ├─ Automated response examples
│   └─ Flask API integration examples
│
├── test_demo.py                    # Test demo
│   ├─ Version number parsing tests
│   ├─ Version extraction tests
│   ├─ Patch determination tests
│   ├─ APK scanning scenario simulations
│   └─ Performance benchmark tests
│
├── test_version_detection.py       # Unit tests (33 test cases)
│
├── README.md                       # Complete documentation (includes quick start guide)
│
└── CLAUDE.md                       # Development guidelines

Core Features

APK Detection

Download Tool