Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Unity

Unity Vendor Cyber Rating & Cyber Score

unity.com

Unity [NYSE: U] offers a suite of tools to create, market, and grow games and interactive experiences across all major platforms from mobile, PC, and console, to extended reality. For more information, visit Unity.com. Download Unity: http://unity3d.com/get-unity We're hiring! Visit our careers site: https://careers.unity.com For support, please email: [email protected] Check us out on our other social channels: Twitter: https://twitter.com/unity Facebook: https://www.facebook.com/unity3d/ Instagram: https://www.instagram.com/unitytechnologies/


Unity A.I CyberSecurity Scoring

Unity
Company Information
Website:https://unity.com/
Employees number:7,122
Number of followers:799,026
NAICS:5112
Industry Type:Software Development
Homepage:unity.com
Unity Risk Score (AI oriented)
Between 750 and 799
logo
UnitySoftware Development
Updated:
05/04/2026
767/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Unity Global Score (TPRM)
xxxx
logo
UnitySoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Unity
UnityFair
Current Score
767Baa (FAIR)
01000
3 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
772Before Incident
MAY 2026
770Before Incident
APRIL 2026
767Before Incident
MARCH 2026
767Before Incident
FEBRUARY 2026
766Before Incident
JANUARY 2026
766Before Incident
DECEMBER 2025
765Before Incident
NOVEMBER 2025
765Before Incident
OCTOBER 2025
764Before Incident
SEPTEMBER 2025
763Before Incident
AUGUST 2025
763Before Incident
JULY 2025
762Before Incident
JUNE 2025
765Before Incident
Vulnerability
16 Jun 2025Unity
Unity Technologies

Critical Arbitrary Code Execution Vulnerability in Unity Engine (CVE-2025-59489)

761After Incident
MEDIUM-4
UNI2392623100625
A critical vulnerability (CVE-2025-59489) was disclosed in the Unity engine, the world’s most widely used game development platform, exposing apps built with affected versions to arbitrary code execution attacks. The flaw allows malicious files to hijack permissions granted to Unity-based games, potentially accessing confidential user data on Android, Windows, Linux, and macOS devices (excluding iOS, Xbox, PlayStation, or Nintendo Switch). While no exploitation has been observed yet, the risk is severe due to Unity’s massive global footprint, powering billions of devices and popular games like Pokémon GO, Genshin Impact, and Call of Duty: Mobile. Unity released patches, and platforms like Steam blocked launches of games using suspicious command-line parameters. Microsoft advised uninstalling vulnerable apps until updates are available. The bug was reported by RyotaK (GMO Flatt Security) during Meta’s Bug Bounty Conference. Though no data breaches or user impact occurred, the vulnerability could have enabled unauthorized data access within the privileges of the affected application, posing significant risks to end-user confidentiality and system integrity.
INCIDENT DETAILS -
TYPE
Vulnerability DisclosureArbitrary Code Execution (ACE)Information Disclosure
IMPACT
Potential access to confidential information on end-user devices (limited to app permissions)AndroidWindowsLinuxmacOSTemporary uninstallation of vulnerable Microsoft apps/games recommendedSteam blocking launches of Unity games with malicious command-line parametersPotential reputational risk due to widespread use of Unity in billions of Android devices globally
DATA BREACH
Confidential information accessible to the vulnerable application (scope limited to app permissions)Medium (dependent on app permissions)
MARCH 2025
781Before Incident
Cyber Attack
13 Mar 2025Unity
Unity Technologies

Customer payment data stolen in Unity Technologies’s SpeedTree website compromise

764After Incident
CRITICAL-17
UNI3702637101425
Unity Technologies, a video game software development firm, suffered a data breach on its SpeedTree website due to malicious code injected into the checkout page. The unauthorized code, active from March 13, 2025, to August 26, 2025, skimmed sensitive customer payment data during purchases. Compromised information included names, addresses, emails, credit card numbers, and access codes of 428 affected individuals. The breach was discovered on August 26, 2025, prompting Unity to disable the website, remove the malicious code, and launch an investigation. The company notified impacted customers, authorities, and offered 12 months of free credit monitoring and identity protection via Equifax. The incident was attributed to a web skimming attack, where threat actors intercepted payment details entered by users during transactions.
INCIDENT DETAILS -
TYPE
Data Breach (Payment Card Skimming / Magecart Attack)
MOTIVATION
Financial Gain (Data Theft for Fraud or Resale)
IMPACT
NamesAddressesEmailsCredit Card NumbersAccess CodesSpeedTree Website (Checkout Page)Operational Impact: Website Disabled During InvestigationBrand Reputation Impact: Potential Reputation Damage Due to Payment Data TheftIdentity Theft Risk: High (Due to PII and Payment Data Exposure)Payment Information Risk: High (Credit Card Numbers and Access Codes Compromised)
DATA BREACH
Personally Identifiable Information (PII)Payment Card DataNumber Of Records Exposed: 428Sensitivity Of Data: High
JUNE 2017
781Before Incident
Vulnerability
16 Jun 2017Unity
Unity Technologies

Unity Game Engine Command-Line Argument Injection Vulnerability (CVE-2025-59489)

779After Incident
CRITICAL-2
UNI3933639100625
A critical vulnerability (CVE-2025-59489) was discovered in Unity, the widely used game engine, allowing malicious apps on the same device to inject command-line arguments into Unity-based games to execute arbitrary code. Discovered by researcher RyotaK (GMA Flatt Security), the flaw affects all games compiled with Unity Editor 2017.1 or later—covering eight years of releases. While Xbox games are unaffected, Windows and Android games are highly vulnerable, with potential remote exploitation via browsers in rare cases. The bug is easy to exploit and poses a massive attack surface due to Unity’s ubiquity in gaming (used by millions of titles). Microsoft and Steam took emergency measures: Microsoft urged users to uninstall Unity games until patched, while Steam blocked launches of Unity games using exploitable command-line parameters. Developers must recompile and redistribute patched versions, creating a logistical challenge. The flaw’s severity is amplified by Unity’s dominance in indie and AAA game development, risking large-scale malware distribution, credential theft, or system takeovers via compromised games. Active exploitation is highly likely given the low barrier for attackers and the sheer volume of vulnerable installations in enterprise and consumer environments.
INCIDENT DETAILS -
TYPE
VulnerabilityCode InjectionSupply Chain Risk
IMPACT
Unity-based games (all platforms)Windows systems running vulnerable Unity gamesPotential browser-based exploitation vectorsGame unavailability on Steam for unpatched titlesTemporary uninstallation recommended by MicrosoftDeveloper patching backlogRecompilation and redistribution required for all affected gamesPlatform-level mitigations (e.g., Steam command-line blocking)Potential loss for indie developers during patching delaysPlatform revenue impact (e.g., Steam sales pauses)User frustration over game unavailabilityTrust erosion in Unity/Steam/MicrosoftUnity: Criticism over 8-year vulnerability windowSteam/Microsoft: Perceived slow response to mitigation

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Unity ?
?
What was Unity's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Unity's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Unity's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Unity's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Unity's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Unity's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Unity's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Unity's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Unity's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Unity's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Unity's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Unity's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Unity ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Unity's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?