TL;DR – Please update SplameiPlay and projects as a security vulnerability was discovered in projects build in the Unity Game Engine 2017.1 and later
We have become aware of a security vulnerability within the Unity Game Engine (CVE-2025-59489) affecting projects built with version 2017.1 and later for the Android, Windows, Linux and MacOS platforms. This directly affects users of SplameiPlay and all Splamei Projects except the ‘Rhythm Plus – Splamei Client’.
We strongly recommend you update to the latest version of all the affected projects which now runs on Unity 2022.3.62f2 which contains the Unity provided fix.
Updates to the affected projects will be available via SplameiPlay, which will automatically update itself, or the official download pages (our website or itch.io). The patched versions are listed below
| Project Name | Patched version |
|---|---|
| SplameiPlay | 4.6 Bloom |
| Bitorpito Classic | N/A |
| Bitorpito Deluxe | 3.0B |
| Dotafib | 2.0B |
According to Unity, there is no evidence that this vulnerability has been exploited or has impacted users and customers. Microsoft Defender has also been updated to detect and block the vulnerability. We recommend that you keep your system and antivirus updated, enable automatic updates and that you avoid downloading suspicious or unknown files and follow the best security practices.
We apologize for any inconvenience this may cause and we hope you understand. We will continue to update our supported projects to patch and fix any bug, issues and vulnerabilities that may present themselves.
For more information, feel free to check out the post made by Unity here.

