I mainly tested a way to get a remote shellWhat about the use of url resources in a scene? Can't someone just create a scene that loads a "resource" at a server controlled by the scene creator? VAM also includes a web browser that can be used to connect a user to any url the scene creator wants, right? And these "features" are enabled by default?
As a client, thought about leaking stuffs with the browser but yeah even easier with an external URL.
Still, the remote thing would be limited to allowed API and local filesystem. So at best, exfiltrate your VaM content.
It might be possible to escape the jail, that's unity specifics, I won't invest more time, I'm just sligjtly more cautions on what I move to my addonpackages dir. I was already for other "malicious" creator who are not able to deliver a proper, small var...
Without further anaylisys, I dont see a big security issue here appart from crashers and exflitrating VaM content. To be confirmed