Unity Technologies has released a patch that fixes a vulnerability allowing third-party code to run in Android-based mobile games. Last week, some experts warned that this vulnerability could pose risks to cryptocurrency users.
Unity stated last Friday that this security patch aims to address a flaw discovered in its game engine in June. Larry “Major Nelson” Hryb, Unity's community director, announced the security update, stating that the vulnerability could allow local code execution and "access confidential information on the end-user devices running Unity-built applications."
He added that there is currently no evidence of the vulnerability being exploited, and "users or customers have not been affected."
Cointelegraph was one of the first media outlets to report on this security vulnerability last Friday.
Sources told Cointelegraph that the vulnerability affects projects since 2017, targeting the Android mobile platform, while also impacting games running on Windows, macOS, and Linux.
A Google spokesperson stated at the time, "Unity has provided a patch to app developers to fix this issue, and developers should update their applications immediately."
Unity recommends that developers download the patched Unity editor update before their next build and use the updated editor to rebuild and re-release published games so that users can update.
Meanwhile, mobile gamers are advised to keep their devices updated, enable automatic updates, and ensure their antivirus software is up to date.
GMO Flatt security researcher RyotaK pointed out in a post that the vulnerability could allow malicious applications installed on the same device to hijack the permissions of Unity applications and could be remotely exploited to execute arbitrary code.
Microsoft issued a security alert on Friday stating that the Windows game development team is updating games or applications that may be affected by the vulnerability, while console games are not impacted.
According to Neowin, Windows Defender has been updated to provide protection, and Android's anti-malware system has also been enhanced.
Meanwhile, according to GameRant, some game developers, including Obsidian Entertainment, temporarily removed several games from all digital stores during the implementation of the fix.
Unity is the industry's leading creator tool platform that helps developers build and grow real-time games and applications across multiple platforms. It supports over 70% of the top mobile games.
Related: Musk announces Grokipedia will launch in two weeks
Original article: “Unity fixes Android mobile vulnerability, says no evidence of exploitation”
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。