update on ps4 bd-j exploit progress (firmware 12.02)
since the last post significant progress has been made on the kernel exploit path
new achievements:
full CPU register control via setcontext ✓
stack pivoting (RSP redirection) ✓
arbitrary syscall invocation from BD-J sandbox ✓
mid-function gadget execution (bypassing function prologues) ✓
kernel binary reverse engineering sysent table handler decompilation ✓
identified a kernel-level vulnerability (not disclosing details)
full chain status on 12.02:
java sandbox escape ✓
arbitrary read/write ✓
aslr bypass ✓
ROP chain with full register control ✓
native syscall execution ✓
kernel vulnerability identified ✓
kernel exploitation in progress
the exploit now has full native code execution capability inside the BD-J process all CPU registers can be set to arbitrary values and any syscall can be invoked directly
a kernel-level bug has been identified and confirmed through binary analysis. currently working on triggering it from userland the last step before achieving kernel read/write
firmware compatibility:
the userland chain works on 12.02, 13.02, 13.50, and 13.52 sony removed the original sunjce_provider.jar AllPermission grant in a recent firmware update but the vulnerability used here is completely unrelated to that code path and remains unpatched
this is still not a jailbreak yet but the gap between userland and kernel is closing the vulnerability is different from any publicly known ps4 exploit and has no CVE
everything runs on stock unmodified firmware
Saudi Software Engineer 🇸🇦 Building. Defending my country, my values, and my people. No tolerance for disinformation or attacks on national sovereignty.