The Unity Corporation has recently confirmed that there is a “significant security gap” in its development tools, affecting games that were developed using the engine as early as 2017, and the official calls for all games or applications using the engine to be repaired. According to the General Lacunae Disclosure (CVE) analysis, “if the application is constructed using an editor version of the Uniity runtime code with a loophole, the assailant may be able to enforce the code on the application’s equipment and steal confidential information.” This loophole affects games developed for Android, Windows, Linux and MacOS systems.

According to PCgamer, the loophole was discovered on 4 June this year and a patch was released on 2 October. Unity rated the gap as highly serious, with a CVSS score of 8.4 (out of 10). The company highlighted, in particular, that although no loopholes had been found to have been exploited, there had been no real impact. However, all games or applications published using 2017.1 and later versions may have this security risk. Eight years have passed since the release of Unity 2017.1, which means that the loophole has been in the engine for eight years. The official suggests that the developers immediately get a patch-up update via Unity Hub or Unity download archive. The Unity Community and Advocacy Director, Larry Herib, clarified in his blog: “There is currently no evidence that the loophole has been exploited, nor has there been any impact on users or customers. We have offered rehabilitation programmes that are immediately available to all developers. The loophole was responsibly disclosed by the security researcher, RyotaK, and we thank him for his cooperation.”

In response to this loophole, Unity “has been updated with major and minor versions of Unity Editors starting with version 2019.1” and “a binary patch for published applications constructed as early as version 2017.1”. Herib recommended that the developers of Windows, Android or MacOS games be developed and released using Unity 2017.1 or more, “reading the guidance document to ensure continuous user safety”, and strongly recommended “downloading the corresponding version of the patches, re-compile and reissue the application”. He also reminded developers to recommend that users “maintain equipment and applications, enable automatic updates and maintain up-to-date anti-virus software”. In addition to Unity’s own measures, Microsoft Defender has updated to detect and intercept the loophole. Valve also issued an update for the Steam platform, “Additional protection for Steam clients”. Several developers, including Black Rock, have responded to the security incident by placing some of the games in the digital store.

In response to reluctance to rebuild the project, Unity released an application fixer tool for Android, Windows and MacOS. However, the tool has limitations: it cannot be used in a build version that has anti-false or anti-fraud features and does not support the Linux platform. The Uniity Network also listed Linux as a high-risk platform, but explained that: “In view of the low risk, the Linux fixer tool was not published. In an environment requiring strict access controls, it is proposed that the Linux application be recomposed using a patched Unity Editor to eliminate loopholes.” With regard to the compatibility concerns of developers, Unity states that “the repair program will not affect most games”. At the same time, the official calls for developers to direct users to keep equipment and applications up to date, with particular emphasis on the risk of using the old version of Unity.