PlayStation 4 Jailbreak
A PlayStation 4 jailbreak is a method to bypass Sony's firmware restrictions, enabling unsigned code execution and homebrew installation by exploiting security vulnerabilities in the PS4's Orbis OS (a FreeBSD derivative).
The PS4 was released in November 2013 and resisted meaningful modification for approximately two years. The first significant breakthrough came in December 2015, when developer CTurt announced a kernel-level exploit for firmware 1.76, followed shortly by the fail0verflow team demonstrating Linux running on the console. These early achievements established the foundation for a decade of continued development.
The jailbreak landscape evolved through several major milestones. The 4.55 jailbreak in 2018 marked the first functional public release for a widely-used firmware version. The 9.00 pOOBs4 exploit in 2021 dramatically broadened the accessible user base by targeting a firmware only two versions deep from the latest release. The most significant expansion came in 2024 with PPPwn, a kernel exploit leveraging an 18-year-old FreeBSD vulnerability that extended jailbreak support to firmware versions 7.00 through 11.00. As of 2025–2026, the Poopsploit (Netctrl) kernel exploit, discovered by TheFloW and implemented via BD-J disc loaders, has been demonstrated running on firmware as high as 13.00[^c1], with a vulnerability scope covering firmware 1.01 through 13.00[^c2]. Combined Blu-ray Disc Java exploit loaders such as HENloader LP support firmware up to 12.52 with Poopsploit extending to 13.00.
The May 2025 Lapse kernel exploit, based on a double-free vulnerability in the aio_multi_delete function[^c16], extended kernel coverage to PS4 firmware 12.02 and PS5 firmware 10.01 before being patched in PS4 12.50 and PS5 10.20[^c15]. In October 2025, Sony released PS4 firmware 13.02 and PS5 firmware 12.02 with security fixes widely believed to patch a kernel exploit reported by developer khoyoko through HackerOne for a $10,000 bounty[^c17], a conclusion drawn from the speed of the response[^c18].
In July 2026, developers Nathan Fargo, ufm42, and DrYenyen published a new CSSFontFace WebKit exploit targeting PS4 and PS5, using a use-after-free bug in the CSSFontFace component of the system's WebKit-based browser[^c4]. The vulnerability affects PS4 firmware 6.00 through 13.52[^c5], though practical exploitation is limited to firmware 6.00 through 11.02 due to WebKit changes on newer versions. GoldHEN 2.4b17.2 expanded payload support to firmware 10.00 and 10.01 via the PPPwn exploit, and GoldHEN 2.4b18 further extended support to firmware 10.50, 10.70, and 10.71[^c13], while the Obliteration project began development of a full PS4 custom firmware with kernel-mode system dumping on firmware 11.00. The PSFree-Lapse v2.3 exploit chain, released in July 2026, introduced stability improvements including a cleanup routine to prevent kernel panics on failed attempts[^c7]. A BD-J sandbox escape vulnerability was formally documented as CVE-2025-64390, affecting firmware versions prior to 13.02[^c6]. Developers also confirmed that the PlayStation View application can access a critical kernel syscall, enabling research toward a full exploit chain for firmware 13.00[^c11].
In July 2026, developer bollars disclosed the Celsius kernel exploit, targeting PS4 firmware up to 13.04 and PS5 firmware up to 12.70 through a heap overflow in the ffs_mount function[^c9]. The exploit requires a USB 3.0 HDD of 250 GB or larger as a trigger and has not reached a practical stage. Sony had already patched the vulnerability in firmware 13.50[^c10]. In April 2026, Korean researcher Gezine announced a zero-day kernel exploit for both PS4 and PS5 that he claims works regardless of firmware version, describing it as the most destructive jailbreak solution since the PS5 launch[^c8]. Independent technical analysis identified the Sony-proprietary syscall sys_fsc2h_ctrl (Syscall 597) as the likely attack surface, involving a race-induced use-after-free vulnerability in the file system controller's state machine[^c12]. Gezine stated he has no plans to publicly release the exploit due to harassment from the community.
Sony released firmware 13.04 in January 2026 with security fixes targeting jailbreak exploits, followed by firmware 13.50 in March 2026 which quietly patched both a Use-After-Free vulnerability and the Celsius kernel exploit[^c3], and firmware 13.52 in June 2026 with explicit security patches. In March 2026, Sony also changed its digital game licensing policy to require a one-time online check to convert temporary licenses to permanent ones, a measure specifically designed to combat a refund-fraud exploit used on jailbroken consoles[^c14]. No public jailbreak is available for firmware above 13.00 as of mid-2026.
Jailbreaking a PS4 carries inherent limitations and risks. All known exploits are non-persistent, requiring re-execution after every cold boot. Once jailbroken, a console cannot be officially updated without losing access to the exploit, and firmware downgrades are generally not possible without hardware-level intervention. The process voids the manufacturer's warranty, risks a ban from the PlayStation Network, and may permanently damage the console if executed incorrectly. While the act of jailbreaking a device one owns is protected under DMCA exemptions in the United States for certain device categories, video game consoles remain explicitly excluded from the jailbreaking exemption as of the 2024 triennial rulemaking, and using the jailbreak to play pirated games constitutes copyright infringement.