vendor:
PlayStation 4
by:
lokihardt from Google Project Zero
8.8
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: PlayStation 4
Affected Version From: 6.20
Affected Version To: 6.50
Patch Exists: YES
Related CWE: CVE-2018-4441
CPE: o:sony:playstation:4
Other Scripts:
N/A
Platforms Tested: None
2018
PS4 6.20 WebKit Code Execution PoC
This repo contains a proof-of-concept (PoC) RCE exploit targeting the PlayStation 4 on firmware 6.20 leveraging CVE-2018-4441. The exploit first establishes an arbitrary read/write primitive as well as an arbitrary object address leak in wkexploit.js. It will then setup a framework to run ROP chains in index.html and by default will provide two hyperlinks to run test ROP chains - one for running the sys_getpid() syscall, and the other for running the sys_getuid() syscall to get the PID and user ID of the process respectively.
Mitigation:
Patch the system with the latest firmware update