• Home
  • Shop
  • Privacy Policy
  • Terms of Service
  • Contact us
Wednesday, February 1, 2023
  • Home
  • Esports
  • PC Games
  • PS4
  • PS5
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X
  • Mobile
  • Game News
No Result
View All Result
GameNewsUSA
wow warcraft alliance horde cataclysm leveling guide
  • Home
  • Esports
  • PC Games
  • PS4
  • PS5
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X
  • Mobile
  • Game News
No Result
View All Result
GameNewsUSA
No Result
View All Result
Home PS4

PS5/PS4: New Webkit vulnerability seems to impact PS4 Firmwares 8.00 to 10.01, and PS5 1.00 to 6.50

January 15, 2023
in PS4
0

A new Webkit vulnerability was disclosed by Google’s Project Zero team. Although it’s too early to say if this could be leveraged for a future exploit on PlayStation consoles, early reports seem to confirm both the PS4 and PS5 are impacted, up to the latest firmwares. This still needs further verification at this point.

PS5 and PS4 Webkit Vulnerability

Google Project Zero team focus on Zero Day vulnerabilities on tools with a large audience. This includes Webkit, the web browser engine used in a vast majority of web browsers nowadays, including the ones used on PS4 and PS5.

Webkit vulnerabilities have been used in the past as an entry point for PS4 and PS5 exploits, including the recent PS5 Hack.

This new vulnerability was disclosed by Project Zero on 2023-Jan-13, and targets CSS functionality in Webkit, with a use-after-free bug.

The Proof of Concept on the PS5 6.50 Browser

Not sure this impacts PS4/PS5 yet (someone needs to check) but potentially? https://t.co/VU5ECuLAUF

— Wololo (@frwololo) January 13, 2023

Webkit CSSCrossfadeValue::crossfadeChanged vulnerability apparently impacts PS4 10.01 and PS5 6.50

Zecoxao has asked people to test the vulnerability, and folks are reporting that “it works”, as the proof of concept (which can be found here) displays a “1”.

To be 100% transparent here, looking at the PoC I’m not entirely sure that showing “1” means a given browser is vulnerable, and I don’t know that anybody’s confirmed the expected behavior, so that will need to be double checked. To be sure, there are cases where a given system (e.g. my Chrome on Windows) doesn’t display anything, so at the very least there seems to be some different behavior involved, which, for the purposes of finding a vulnerability, is a good sign.

Echo Stretch has a video showcasing the PoC running on multiple systems:

You can test the vulnerability on your own console by going to http://es7in1.site/test.html. Again, at this point, I’m not sure anybody has confirmed 100% that displaying a “1” on the page (or not displaying it, for that matter), is proof that the system is vulnerable. I’ll update as soon as I have details on that.

If the vulnerability turns out to actually be something worth investigating, Sleirsgoevy will be looking into it, according to Zecoxao.

i think the almighty @sleirsgoevy will work on the webkit meme. stay tuned!

— Control_eXecute (@notzecoxao) January 14, 2023

Details on the CSSCrossfadeValue::crossfadeChanged Webkit Vulnerability

Related Posts

PS4

PS Plus February 2023 FREE PS4 and PS5 games reveal date, time and leaked line-up revealed | Gaming | Entertainment

February 1, 2023
PS4

Drift Season 1 Arrives March 8 for PS4, Xbox One, PC, and Mobile

February 1, 2023
PS4

The Last of Us HBO Gets More Viewers Than Ever for Second Week in a Row

January 31, 2023
PS4

Loop8: Summer of Gods delayed to June 1 for PS4, Xbox One, and Switch in Japan; June 6 for PC

January 31, 2023
PS4

Ghost of Tsushima Movie Gets Cautious Update From John Wick Director

January 31, 2023
PS4

Is Resident Evil Village VR support coming to PS4?

January 30, 2023
Load More
Next Post

Xbox vs PlayStation: "The Big Bang Theory" Sitcom Genius Sheldon Cooper Once Ended the Console Debate but…

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Esports News

ESL FACEIT Group expands its viewing services for fans with Twitch and YouTube – European Gaming Industry News

February 1, 2023

Esports explained: Looking at the industry and history

February 1, 2023

Amazon University Esports returns for Spring Split 2023 with Apex Legends, a tour and a new University Leaderboard, with the University of Warwick (unsurprisingly) at the top already

January 31, 2023

Guild Esports PLC’s latest annual results see high-profile sponsorship deals take centre stage

January 31, 2023

PC Games

PS2 4K emulation on the M2 Pro Mac mini is real, and it’s spectacular

February 1, 2023

UK fishing fleet may become ‘unviable’ without switch to net-zero, says report

February 1, 2023

The Crew Motorfest Arriving This Year

February 1, 2023

PS Plus February 2023 FREE PS4 and PS5 games reveal date, time and leaked line-up revealed | Gaming | Entertainment

February 1, 2023
No Result
View All Result

Categories

  • Esports News
  • Game News
  • Mobile
  • PC Games
  • PS4
  • PS5 News
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X

PS4

PS Plus February 2023 FREE PS4 and PS5 games reveal date, time and leaked line-up revealed | Gaming | Entertainment

February 1, 2023

Wii U

PS2 4K emulation on the M2 Pro Mac mini is real, and it’s spectacular

February 1, 2023

Microsoft Is Removing Dozens Of Games From The Xbox 360 Marketplace In February

February 1, 2023

Recent News

PS2 4K emulation on the M2 Pro Mac mini is real, and it’s spectacular

February 1, 2023

UK fishing fleet may become ‘unviable’ without switch to net-zero, says report

February 1, 2023
  • Home
  • Shop
  • Privacy Policy
  • Terms of Service
  • Contact us

© 2022 GameNewsUSA

No Result
View All Result
  • Home
  • Esports
  • PC Games
  • PS4
  • PS5
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X
  • Mobile
  • Game News

© 2022 GameNewsUSA