Handelabra Response to Unity Security Advisory CVE-2025-59489
On October 3rd, 2025 we were notified by Unity and Steam about a security issue that affects all games developed with Unity, including our digital tabletop games, on Android, Windows, Linux, and macOS operating systems. We have immediately taken action to prepare updates to resolve the problem as soon as possible.
It’s important to note that there is no evidence that any exploits or malicious code are in the wild that use the vulnerability at this time. Furthermore, Unity has been working with platform partners to limit the potential risks:
On Steam, Valve has released a Steam Client update to block any exploits.
Microsoft Defender has been updated and will detect and block the vulnerability.
On Android, the built-in malware scanning and other security features will help reduce risks to users posed by this vulnerability.
The vulnerability presents a much lower risk on Linux compared to Android, Windows, and macOS.
For all other Unity-supported platforms including iOS, there have been no findings to suggest that the vulnerability is exploitable.
On your side, please make sure to keep auto-updates on to ensure you get security updates promptly, and use antivirus and security protection software such as Microsoft Defender.
We are working on updating all of our games as per Unity’s instructions. Here is the current status (updated October 3, 2025):
Sentinels of the Multiverse: hot fix update in QA testing
Sentinels of Earth-Prime: hot fix update in QA testing
Spirit Island: update planned for release with Nature Incarnate launch; hot fix may ship earlier if time allows
Aeon’s End: update planned for release with phone support launch; hot fix may ship earlier if time allows
One Deck Dungeon: hot fix update in development
One Deck Galaxy: hot fix update in development
Bottom of the 9th: hot fix update in research stage as this game has not been actively maintained
Sentinels of the Multiverse (Learn to Play Edition): hot fix update in research stage as this game has not been actively maintained
Sentinels Sidekick: This app is not made with Unity and so is unaffected.