Impact
A privilege escalation vulnerability exists in the PlayStation 4 firmware, allowing exploitation of the BD-J sandbox through a malformed Java Archive file. By escaping the sandbox, an attacker can execute code with elevated privileges on the console, potentially enabling full control over the device.
Affected Systems
Sony PlayStation 4 consoles running firmware versions 13.00, 13.01, or 13.02 are affected. The vulnerability resides in the BD‑J (Blu‑ray Disc Java) sandbox that is intended to isolate Java applications from the underlying system.
Risk and Exploitability
The CVSS score is not provided, and no EPSS information is available. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploits as of now. Nevertheless, escaping the BD‑J sandbox grants privilege escalation, which is a high‑severity flaw. Exploitation likely requires a malformed JAR to be processed by the console, so local or physical disc access is a prerequisite. While no public exploit has been disclosed, the potential impact justifies immediate patching once an update is available.
OpenCVE Enrichment