Unity Technologies has patched a critical vulnerability that could have allowed malicious code execution in Android-based games built using its engine — a flaw that some experts warned might have been exploited to target crypto users.

The company confirmed on Friday that it had rolled out security updates addressing the issue, which was originally discovered in June. The vulnerability, according to Unity’s Director of Community Larry “Major Nelson” Hryb, could have enabled local code execution and unauthorized access to sensitive information on users’ devices.

However, Hryb emphasized that there is currently no evidence of the flaw being actively exploited.

“We have found no indication that this vulnerability has been used in the wild or that any user or customer data was affected,” he said.

Sources who spoke to Cointelegraph said the vulnerability affected Android-based Unity applications dating back as far as 2017 and could also impact games running on Windows, macOS, and Linux.

A Google spokesperson confirmed that Unity had been working with their security teams to address the issue:

“Unity is making a patch available to app developers to fix this issue, and developers should update their apps immediately.”

Unity urges developers to rebuild and republish apps

Unity has advised all developers using its platform to download the patched Unity Editor before their next build, rebuild all previously released games, and republish them to ensure players receive the fixed versions.

Mobile gamers were encouraged to keep their devices updated, enable automatic app updates, and maintain active antivirus protection.

GMO Flatt Security researcher RyotaK, who first analyzed the bug, revealed that it allowed malicious apps installed on the same device to exploit Unity-built applications and hijack their permissions — a vulnerability that could theoretically be used to execute arbitrary code remotely.

Among Us is a popular game created with Unity. Source: Epic Games

Microsoft and game studios respond

Microsoft also issued a security advisory on Friday, confirming that Windows Defender and Android’s built-in anti-malware systems have been updated to detect potential exploit attempts. The company clarified that console games were not affected.

Several developers, including Obsidian Entertainment, temporarily pulled their Unity-based titles from digital storefronts to apply the fix.

“We’re taking every precaution to ensure all affected titles are fully patched and safe for players,” said a Microsoft spokesperson.

Unity, which powers more than 70% of the top 1,000 mobile games, remains one of the most widely used real-time 3D development platforms globally. Its tools are central to many blockchain-integrated games, metaverse projects, and NFT experiences — making the patch particularly significant for the crypto gaming ecosystem.