Google Play still flags Device & Network Abuse after rebuilding with Unity 6000.0.68 (patched version)

Hello Unity Team,

I am facing an ongoing Google Play policy warning related to a Unity Android security vulnerability.

Previously, Google flagged my app under Device and Network Abuse policy, stating that apps built with Unity 2017.1 and later contain a security vulnerability. Following Unity’s security advisory, I rebuilt and uploaded my app using a patched Unity version.

I have now rebuilt the app using Unity 6000.0.58, performed a clean build, and uploaded a new AAB. However, Google Play still reports the same policy warning for the new version.

I would like to confirm:

  1. Does Unity 6000.0.58 fully resolve the Android runtime vulnerability referenced in Google Play’s notice?
  2. Are there any additional required steps (NDK version, build settings, or known plugin issues) that could cause Google Play to still detect the vulnerability?
  3. Is there a recommended way to verify that the generated libunity.so / libil2cpp.so binaries are fully patched?

There is no evidence of exploitation, and I am actively rebuilding and re-uploading to ensure full compliance.

Any official guidance or confirmation would be greatly appreciated.

Thank you.

1 Like