Work at Unity Technologies? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Unity Technologies is committed to helping game developers build games easily and in a secure fashion. As part of this we encourage security researchers to test our security and find the things we miss. We look forward to seeing what you find! What we expect from you Send us a full, detailed report (discussed below) as soon as possible upon discovery of a potential security issue Refrain from any disclosure to the public or a third-party before resolution of the issue. Make a good faith effort to avoid privacy violations, destruction/modification of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder. If you have compromised a Unity server you will not use it for further chained attacks. Clean up after your tests. Both automated and manual tests can leave a number of dummy and spam entries, so we ask you to do your best to remove them after you're finished. By sending us a report or otherwise participating in our bug bounty program, you agree that you have read and understood this policy and agree to all its terms. What you can expect from us We will respond to your bug report as quickly as we can. We will keep you updated on the progress of getting the issue fixed. Reward decisions are made once a week. Ratings/Rewards: For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Scope
9 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| api.unity.com | api | ✓ bounty | not set |
| cloud.unity.com | website | ✓ bounty | not set |
| id.unity.com | website | ✓ bounty | not set |
| Latest Supported LTS Versions of the Unity Editor - Unity 6.x.x Standard LTS, Unity 2022.3.x / 2021.3.x xLTS (enterprise license) | other | ✓ bounty | not set |
| Latest Version of the Unity Hub | other | ✓ bounty | not set |
Show all 9 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| pay.unity.com | website | ✓ bounty | not set |
| player-login.unity.com | other | ✓ bounty | not set |
| services.unity.com | api | ✓ bounty | not set |
| store.unity.com | website | ✓ bounty | not set |