Hackers have been circling the PS5 for almost a year now, and it appears they may have finally managed to jailbreak the 2020 hardware with a new kernel-level exploit first discovered on the PS4. While it doesn’t allow access to execute certain types of code, the exploit has made it possible for at least one person to reportedly run Kojima’s Silent Hill demo prequel, P.T., on their PS5, and will likely have massive implications as more people explore the jailbreak.
The PS5 IPV6 Kernel exploit, discovered by “PlayStation hacking god” Andy “TheFloW” Nguyen last month, now has a way to be implemented, as tweeted over the weekend by hacker SpecterDev. It relies on a previously known vulnerability in Webkit, the PS5’s web browser technology, that works on PS5s running firmware 4.03, and possibly earlier versions as well.
The exploit works by having the PS5 access a web server housed on a local PC that contains SpecterDev’s implementation of the hack. It apparently works around 30 per cent of the time, giving users access to the console’s debug mode, and thus letting them run software outside of what was originally intended by Sony.
Here’s a demonstration of the new exploit that was tweeted yesterday:
— Echo Stretch (@StretchEcho) October 3, 2022
“This exploit gives us read/write access, but no execute,” reports console hacking blog Wololo.net. “This means no possibility to load and run binaries at the moment, everything is constrained within the scope of the ROP chain. The current implementation does however enable debug settings.”
Even so, the early exploit was still enough to let Dark Souls archeologist Lance McDonald install abandoned PS4 micro-horror game P.T., which isn’t officially backward compatible on the PS5:
The PlayStation 5 has been jailbroken. pic.twitter.com/54fvBGoQGw
— Lance McDonald (@manfightdragon) October 3, 2022
The IPV6 webkit exploit was discovered by TheFloW two years ago on the PS4. He found it again on the PS5 and reported it to Sony in January 2022. “It seems like their patch somehow got reverted when doing FreeBSD9 to FreeBSD11 migration,” he recently told Motherboard. TheFloW subsequently received a $US10,000 ($13,882) bounty from Sony and the vulnerability was disclosed on the site HackerOne on September 20, 2021.
Ever since, others in the PlayStation hacking community have been working on ways to exploit the vulnerability to jailbreak both the disc-based PS5 and its all-digital counterpart. Console manufacturers try to keep their systems locked down in part to ward off piracy, and today’s jailbreak is likely just the beginning of hackers poking holes in that security. Sony didn’t immediately respond to a request for comment.
The Cheapest NBN 1000 Plans
Looking to bump up your internet connection and save a few bucks? Here are the cheapest plans available.