confirmed on ps4 firmware 13.52
after exploitation:
System.getSecurityManager() = null
sun.misc.Unsafe is accessible
restricted System fields are exposed
this is not a kernel exploit and not a jailbreak yet, but the userland issue affects 13.52
the full userland chain has been tested end to end on stock firmware 12.02
to the best of my knowledge, this issue has no public cve and is completely different from gezine's bd-jb, which relied on a verifier bug leading to type confusion
current progress on 12.02:
java sandbox escape ✓
arbitrary read/write ✓
aslr bypass ✓
basic ROP chain execution ✓
native code execution via syscalls ✓
remaining for a full jailbreak:
kernel exploit (not there yet)
everything above runs on stock firmware with no modifications. the userland chain is fully working and only needs a kernel entry point to complete the jailbreak.
Saudi Software Engineer 🇸🇦 Building. Defending my country, my values, and my people. No tolerance for disinformation or attacks on national sovereignty.