PS4 (Update) A New PS4 Kernel Exploit (7.02) Released by TheFl0w (PS4 6.72 Jailbreak next canidate)

The PlayStation 4 Hacking/Homebrew Scene has been a unique journey in comparison to other PlayStation platforms even those in the firmware era (psp/vita/ps3). The PS4 itself has been a bit unique, while development has always been there it has came at a slower pace and for a limited audience on back dated firmware releases. We have seen several exploited firmware on the PlayStation 4 (PS4) we started the show off with 1.76 and then through a few exploits we eventually climbed the ladder and moved onto 5.05 firmware and currently that has been the latest firmware exploited when the console has aged to 7.5x era . So a new exploit is in the desire list for many.

Recently (back in March) well known developer theflow0 most notably for his work recently in the PS Vita scene. His works included various exploits and also some great homebrew projects like VitaShell. So when the developer decided to turned his attention to the PS4 (see our coverage here) and announced that he had a 6.20 kernel exploit and advised the public not to update your PS4 console's firmware past 6.20, it excited many, At the time many would have updated already (v7.x), its did become a much bigger window then the current 5.05 and upgrades existing exploited console's with a new exploit. So this was eager news for many waiting patiently and sadly also fuel for the twitter trolls out there in social media land.

48790761922_b9a81a53dd_o.png

Then, several weeks ago you may of heard of a new bug bounty program for PlayStation (via https://hackerone.com/playstation). When this program was announced just recently there was alot of opinions shared and various disagreements in ideology arose and that became the focus of arguments it seemed. Following some of those disputes hacker thefl0w went to twitter on June 25 with the following:


"PS4 scene, you're starting such a drama over nothing. I was actually planning to disclose something in a few weeks/months (which I will still do...) and after that, I'd like to announce my retirement, even if I was never part of that toxic and entitled "scene".

Then today thefl0w and hackerone.com (via PlayStation Bug Bounty) announced the ps4/vita hacker has claimed a $10,000 bounty for a kernel exploit on the PS4 for firmware 7.02 (patched in 7.50) (however for 7.02 support there will need to be a webkit exploit found and released to the public, but there is one released in the public that support 6.72.) Here is what theflow0 has to say about the exploit released on July 6:
via twitter (July 6)
Here you are, https://hackerone.com/reports/826026, PS4 kernel exploit for FW 7.02 and below. Vulnerability discovered on 2019-06-09. This must be chained together with a WebKit exploit, for example https://github.com/Fire30/bad_hoist for FW 6.50.
July 6
Apologies, the WebKit exploit works upto FW 6.72.

  • So, what does this mean?
    We will be moving on from 5.05 in the future as the pieces are put together by the community. with 6.72 more then likely being the focus since we have a public webkit already and the wait will be for a 7.02 webkit exploit to be found and released to the public as that is needed for entry point to use the kernel exploit..

    thefl0w entry in the PS4 scene appears to be a brief but explosive one as the developer has also decided to call his short PS4 tenure quits confirming what he said on June 25 as those feelings seemed to stemmed from various disagreements and attitude's he did not like (more details can be found on his twitter)

    To summarize, A developer got $10,000 for releasing his Exploit, an exploit that many are going to get to use and upgrades from 5.05 It does look like that bounty program is not the end of the world after all as some were suggesting,

    Stay Tuned as this is sure to mature over the next several days/weeks,
    Do not update past 6.72 and if on 5.05 currently stay until been properly prepared for public consumption.


    .Exploit Disclosure @: hackerone.com


Updates:
 
Last edited:
Wow.....should i go for it ...
or could it screw anything i already have...
psn games digital that i bought threw psn...
 
Wow.....should i go for it ...
or could it screw anything i already have...
psn games digital that i bought threw psn...
There are some games that don't work due to mira.It would be better to wait,unless you are in a hurry to run specific backups of games and you are above 5.05.Homebrew isn't compatible yet since it needs to be ported over for 6.72.
 
Last edited:
if anyone is thinking about updating, I'd suggest using the db and sg payload first. I've heard that the app.db won't show fpkg games after updating or the database gets corrupted a lot. I've also heard that rebuilding the database doesn't work correctly with fake pkg games, so best to back up that stuff in case the unthinkable happens.
 
does anyone know what firmware final fantasy vii remake requires? I was going to get it, but not if it's like 7.50. the latest update may be. I couldn't find it on orbis modding or the other pkg finder site. it's unlisted. it will tell you if it requires over 5.05, but the game itself is not present (possibly due to not being exploitable at present).
Final Fantasy VII requires Firmware 7.02, and was built using the 6.50 SDK, hope that is enough, i bought it day one before the 7.50 was required just a few days later.

Sent from my G8141 using Tapatalk
 
Final Fantasy VII requires Firmware 7.02, and was built using the 6.50 SDK, hope that is enough, i bought it day one before the 7.50 was required just a few days later.

Sent from my G8141 using Tapatalk

I'll just have to wait longer. I read that 8.00 beta is either soon to be released or is released. perhaps, the bounty program has found another exploit. this time, for 7.51?
 
I'll just have to wait longer. I read that 8.00 beta is either soon to be released or is released. perhaps, the bounty program has found another exploit. this time, for 7.51?
I doubt 8.00 was made to patch up an exploit as its main features are party updates
 
Just one question for 5.05 users..
will i be able to convert a Psn game i bought online...
to a pkg or a backup folder game...
 
Just one question for 5.05 users..
will i be able to convert a Psn game i bought online...
to a pkg or a backup folder game...

btw, I recently wrote a tutorial on backing up games. I don't know if it's changed any with 6.72. all of your games will be packages. the game md5 matches the one on the ps4 after installation. the game is named app.pkg for all games, just different title id folder. the game is then decrypted into a partition named "sandbox." that's how the app dumper works. it takes those files, then puts them on the flash drive. make sure you have one that's at least 128GBs. it's recommended you do one game at a time, since the system, by default, will shutdown once a game dump has completed, and you don't want to get confused. however, I think you can do more than one if you want. my flash drive just isn't big enough for two games in a lot of cases. it's 128GBs.
 
I would think that hackers capable of exploiting new firmwares would have a salary of $10,000 or over per month, so the bounty is not as attractive to them as fame :)

P.S As many, I don't care about piracy, only about games preservation / homebrew / emulators / extended backwards compatibility.
 
I would think that hackers capable of exploiting new firmwares would have a salary of $10,000 or over per month, so the bounty is not as attractive to them as fame :)

P.S As many, I don't care about piracy, only about games preservation / homebrew / emulators / extended backwards compatibility.

not necessarily. I'm pretty sure theflow was or is a student at a university. I remember reading that in his twitter I believe.
 
I have one unit with 6.20 just fixed this week and I will test this coming week. I would like to keep 6.20 and run any exploit or should I update?
 
Last edited:
He is more than capable earning that much or even more. What Geohot is up to atm? :)

geohot was working for google, but then he started his own automated car business. he was at the expo where they first showed off the ps4 exploits. he wasn't there for that. he was there to promote his business, but it showed him talking to the hackers of the ps4.
 
I can't remember which, but I'm think it was either an adobe product or photoshop, but I saw George Hotz's name listed in programmers. I think it's the same one.
 

Featured content

Trending content

Back
Top