Critical Unity Engine Flaw Prompts Microsoft and Obsidian to Pull Fallout Shelter, Top Steam Games

Unity engine engineers recently uncovered a major security vulnerability in their popular game development platform, a flaw that existed for nearly ten years. This critical breach could potentially allow the viewing and theft of user data within any application built with the engine. While a recent patch has fixed the core vulnerability, all affected games require an immediate update to fully resolve the issue for players.
Encryption for Beginners: What is it and Why is it Important? What is a Firewall and How Does It Work?
While many titles have already received the necessary security patch, a few notable games are still awaiting correction, such as Overcooked 2. Other major companies, including Microsoft and Obsidian Entertainment, took decisive action by temporarily removing popular games from digital storefronts to implement the fixes before allowing them back on sale. Affected high-profile Steam games include Fallout Shelter, Pillars of Eternity II: Deadfire, Pentiment, Wasteland Remastered, Wasteland 3, and more.
Affected Games, Security Fixes, and Potential Risks
The vulnerability extends beyond games solely built on the Unity engine. Some titles developed on other platforms, like Avowed (made with Unreal Engine 5), also have affected components. For example, the Avowed Deluxe Edition’s artbook was built using the vulnerable Unity engine, making the entire package susceptible to the breach. Another significant game affected by this specific exploit is Grounded.
The security vulnerability affecting our games that use Unity has recently been identified.
As a precaution and to keep you safe, we have temporarily removed the following titles and products from digital storefronts while we implement the necessary updates to address the issue:…
— Obsidian (@Obsidian) October 3, 2025
According to a statement from Unity engineers, the vulnerability itself did not result in any known exploitation or data breaches for users. The issue lies in the fact that programs created with the engine are susceptible to an insecure file loading process, which creates a possible vector for local files to be included in sophisticated cyberattacks, depending on the operating system. This means that for a malicious third party to successfully breach and steal personal user data, harmful files would first need to be present on the target computer.
Furthermore, the execution of any such malicious code would be confined to the vulnerable application’s existing privilege level. Therefore, the scope of any malware exploiting this flaw would be limited and would only become truly dangerous if the game was run in administrator mode. Even with these limitations, vigilance is key: if any of your games request an update, download and install the security patches immediately.
Read also: What is Phishing and How to Protect Yourself? What is Social Engineering? Learn to Identify and Protect Yourself from Scams What is a Zero-Day Vulnerability?
VIDEO | Are GAMES becoming more EXPENSIVE and WORSE, or not?
Read the full story on Canaltech.
What did you think of this news regarding the Unity vulnerability and its impact on major titles like Fallout Shelter? Leave a comment below and/or share it on your social media. This way, we can inform more people about the hottest things in technology, science, innovation, and gaming!
This news was originally published in:
Original source
