Executive brief
A security vulnerability in the PlayStation 4 allows for a sandbox escape when playing specially crafted Blu-ray discs. This flaw could allow unauthorized software to run with higher privileges than intended, potentially leading to the bypass of digital rights management or the execution of custom code. To exploit this, an attacker would typically need to provide a physical disc containing a malicious file to the console.
Technical details
A privilege escalation vulnerability exists in the Sony PlayStation 4 firmware (versions 13.00 to 13.02) within the Blu-ray Disc Java (BD-J) environment. The vulnerability is characterized as a sandbox escape triggered by a malformed JAR file processed during Blu-ray playback. By exploiting this flaw, an attacker can bypass the restricted execution environment intended for disc-based applications to gain elevated privileges on the system. This typically requires physical access to the console to insert a crafted Blu-ray disc. The vulnerability was disclosed via HackerOne.
Affected products
- Sony PlayStation 4 Firmware 13.00 - 13.02
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory