Research tools and kernel offsets for PS4 firmware 13.04–14.00 security research.
1304.c/1304.h— Complete kernel offsets for FW 13.041400.c/1400.h— Complete kernel offsets for FW 14.001352_offsets.txt— Partial kernel offsets for FW 13.52src/org/bdj/SuidScanner.java— SUID/SGID binary scanner via BD-JBscanner_1304.iso— Pre-built ISO for testingcve_analysis.md— CVE analysis for PS4 kernel
- ✅ BD-JB — Sandbox escape working (ps3120/Gezine)
- ✅ WebKit DOM postMessage — Vulnerability present (confirmed on hardware)
- ✅ WebKit DOM getters — Vulnerability present (confirmed on hardware)
- ✅ WebKit LLInt OOB — Vulnerability present (confirmed on hardware)
- ✅ PlayStation Vue — Installed, potential Celsius entry point
- 🔥 Celsius (ffs_mount) — Integer overflow in ffs_mountfs(), works up to 13.04, patched in 13.50. Discovered by bollars.
- 🔥 CVE-2026-49415 — execve TOCTOU race condition, affects all FreeBSD versions. Under investigation.
- 2026-09-24: FW 14.00 kernel offsets added (source: Al-Azif, Scene-Collective/ps4-hen pre-release-main-182)
- 2026-09-21: PS4 13.04 jailbroken with GoldHEN v2.4b18.12 (SiSTRo)
- 2026-09-19: PS4 13.04 jailbroken with HEN 2.2.0 (webkitty.arabpixel.net)
- 2026-09-16: Sony releases FW 14.00 ("stability improvements")
- 2026-07-21: MasterMaind confirms BD-J sandbox escape up to 13.50/13.52
- 2026-07-21: etaHEN updated for PS5 up to 12.70
- 2026-07-18: Celsius (ffs_mount KEX) announced by bollars
- 2026-07-18: 13.04 kernel offsets published
Scans the PS4 filesystem for SUID/SGID binaries via BD-JB userland exploit.
Uses native FreeBSD syscalls (open, getdents, stat) via BD-JB's Java API.
Results displayed on screen and saved to USB at /mnt/usb0/suid_scan.txt.
- Burn
scanner_1304.isoto BD-R at 4x speed - Insert USB drive (FAT32/exFAT) in PS4
- Insert BD-R disc
- Results appear on screen and saved to USB
Full offsets in 1304.c — based on 13.02 (identical kernel) verified by Pharaoh2k's offset table.
Full offsets in 1400.c — from Al-Azif's Scene-Collective commit (Sep 19, 2026).
Key data addresses (unchanged from 13.04):
PRISON0 = 0x111FA18
ROOTVNODE = 0x2136E90
SYSENT = 0x1102B70
ALLPROC = 0x1B28538
PRISON0 = 0x111FA18
ROOTVNODE = 0x2136E90
SYSENT = 0x110A760
unknown1 = 0x4D6D0
unknown2 = 0xE6C60
See cve_analysis.md for detailed analysis of:
- CVE-2026-7270 — execve buffer overflow (DISCARDED: function not present in FreeBSD 9)
- CVE-2026-49415 — execve TOCTOU race (CANDIDATE: SUID code confirmed in FreeBSD 9)
- Celsius / ffs_mount — Integer overflow in ffs_mountfs() (CONFIRMED for 13.04)
The vulnerability is in ffs_mountfs() in sys/ufs/ffs/ffs_vfsops.c:
size = fs->fs_cssize; // attacker controlled
if (fs->fs_contigsumsize > 0)
size += fs->fs_ncg * sizeof(int32_t); // INTEGER OVERFLOW
size += fs->fs_ncg * sizeof(u_int8_t); // INTEGER OVERFLOW
space = malloc((u_long)size, M_UFSMNT, M_WAITOK); // small malloc
// Later:
for (i = 0; i < fs->fs_ncg; i++) // huge loop
*lp++ = fs->fs_contigsumsize; // HEAP OVERFLOWfs->fs_ncg comes from the UFS superblock (attacker controlled). A large value causes integer overflow in the size calculation, resulting in a small malloc but massive heap overflow.
Requirements: BD-J or Vue entry point + 250GB+ HDD with malformed UFS image.
A malformed MP4 file (mutado_race.mp4) crashes Media Player and SHAREfactory:
- Crash confirmed on FW 11.00 (likely present on 13.04)
- Bug in
moov.udta.metaatom parsing - Child atom declares 190 bytes in 90-byte container → heap overflow
- Injection points at offsets 0x833 and 0x885
- Error 34878-0 on SHAREfactory, freeze on Media Player
Credit: Shunsui (discovery and analysis)
- BD-JB-1250 by ps3120/Gezine
- Scene-Collective/ps4-hen for offset format
- PPPwn by TheFloW for exploit architecture reference
- ps3120 — BD-JB-1250 and bdj1304.iso
- Gezine — BD-JB vulnerability discovery
- Scene-Collective — ps4-hen open source offsets
- Al-Azif — 14.00 kernel offsets (Scene-Collective/ps4-hen)
- Pharaoh2k — 13.04 kernel offsets verification
- SiSTRo — GoldHEN v2.4b18.12
- bollars — Celsius (ffs_mount) discovery
- MasterMaind (@ASaudidos) — BD-J escape confirmation up to 13.52
- Shunsui — MP4 parser vulnerability discovery and analysis
- Victor — Celsius confirmation and technical guidance
This research is for educational and security research purposes only.