The GlitchMod knowledge base

Exploit Chart

The following chart shows all compatible hacks for each firmware version.

8 min readUpdated Oct 9, 2026

The following chart shows all compatible hacks for each firmware version.

  • See the Getting Started page for instructions on how to use the exploits on this page.
  • See the ★ Frequently Asked Questions (FAQ) ★ page for information about jailbreak usage and homebrew.
    • On this page, "theoretical" means an exploit is not implemented on said firmware but should be possible.
Firmware Userland Exploit(s) Kernel Exploit(s) Course of Action Information
Older than 5.05
  • Various
  • BadIRET (1.76)
  • NamedOBJ Exploit (<=4.07)
  • BPF Race Condition (4.55 to 5.03)
Either stay for archival purposes, or update to 5.05 Homebrew support is very limited, and even more games will require backports. Anything before 4.07 doesn't even have a homebrew enabler implementation.
5.05/5.07
  • CVE-2016-1859 (Webkit)
  • CVE-2017-7005 (Webkit, used with kernel exploit)
  • BPF Race Condition
Stay on current firmware The Standard Jailbreak page details the instructions on how to jailbreak this firmware version.

Considered the gold standard firmware because of its original exploits having stability and success rate. However, most games will require backports.

5.50 to 6.51
  • bad_hoist (Webkit)
  • IPV6 UaF (Implemented on 6.7x)
Update to 6.72 or 9.00 and not above This firmware range has exploits that are highly unstable. As such, it's easier to just update to 6.72 or 9.00.
6.70 to 6.72 Either stay, or update to 9.00 and not above The Standard Jailbreak page details the instructions on how to jailbreak this firmware version.

Original exploits were optimized overtime to have good success rate and stability. 9.00 - 9.60 may still be desired due to more game/homebrew support, in addition to the official built-in CBOMB fix.

7.00 to 7.55
  • buildBubbleTree exploit (Webkit, original)
  • psFree (Webkit)
  • Vue After Free exploit
  • IPV6 Double Free
  • PPPwn
  • Lapse
  • Netctrl/Poopsploit (Theoretical)
Recommended exploit is either the web browser (Webkit), as seen with the Standard Jailbreak tutorial, or VueAfterFree.

7.XX firmwares do have native Webkit/kernel exploits, which used to have poor performance, but with the release of Lapse it is a firmware you can easily stay on, though 9.00 may still be desired due to more game disc support, in addition to the official built-in CBOMB fix. PPPwn is not recommended on this firmware range.

8.00 to 8.52
  • psFree (Webkit)
  • Vue After Free exploit
  • PPPwn
  • Lapse
  • Netctrl/Poopsploit (Theoretical)
Recommended exploit is the web browser (Webkit), as seen with the Standard Jailbreak tutorial.

8.xx also has VueAfterFree, which is a nice alternative to Webkit, and PPPwn, which is not recommended.

9.00
  • CVE-2021-30858 (Webkit, used w/ pOObs4)
  • psFree (Webkit)
  • CSSFontFace (Webkit)
  • Save file exploit for Artemis engine games (Lua Loader)
  • Netflix exploit (Netflix-N-Hack)
  • Mast1c0re (PS2 emulator exploit)
  • BD-JB (Blu-ray Java exploit)
  • Vue After Free exploit
  • exfathax (pOObs4)
  • PPPwn
  • Lapse
  • Netctrl/Poopsploit
Stay on current firmware Recommended exploit is the web browser (Webkit), as seen with the Standard Jailbreak tutorial.

VueAfterFree and BD-JB are good alternative options to Webkit. However, VueAfterFree requires the PS4 to have a LAN connection, whereas BD-JB doesn't need any online connection, and Webkit exploits need at least temporary access to LAN or internet to cache the exploit website on your PS4's hard drive for offline use. This firmware also has access to using Netflix (with Netflix-N-Hack) and game save exploits (such as Lua Loader and Mast1c0re) to jailbreak the console, but these methods are more of a novelty to the end user due to this firmware having access to Webkit/BD-JB/VueAfterFree.

9.00 firmware can be seen as another "gold standard' version, as its original exploit also has a high success rate with high stability, in addition to an official built-in fix by Sony to address the "CBOMB" issue, but does not fix time and date. The original 9.00 exploit requires an extra USB drive for the initial exploit, but can also use the newer Lapse exploit, which doesn't require the exfathax USB drive. PPPwn is not recommended on this firmware range.

PPPwn is not recommended on this firmware version.

9.03 to 9.51
  • psFree (Webkit)
  • CSSFontFace (Webkit)
  • Save file exploit for Artemis engine games (Lua Loader)
  • Save file exploit for Ren'Py engine games (YARPE)
  • Netflix exploit (Netflix-N-Hack)
  • Mast1c0re (PS2 emulator exploit)
  • BD-JB (Blu-ray Java exploit)
  • Vue After Free exploit
  • PPPwn
  • Lapse
  • Netctrl/Poopsloit
Either stay, or update to 9.60 and not above Recommended exploit is the web browser (Webkit), as seen with the Standard Jailbreak tutorial.

VueAfterFree and BD-JB are good alternative options to Webkit. However, VueAfterFree requires the PS4 to have a LAN connection, whereas BD-JB doesn't need any online connection, and Webkit exploits need at least temporary access to LAN or internet to cache the exploit website on your PS4's hard drive for offline use. This firmware also has access to using Netflix (with Netflix-N-Hack) and game save exploits (such as Lua Loader and Mast1c0re) to jailbreak the console, but these methods are more of a novelty to the end user due to this firmware range having access to Webkit/BD-JB/VueAfterFree.

PPPwn is not recommended on this firmware range.

9.60 Stay on current firmware
10.00 to 11.00
  • CSSFontFace (Webkit)
  • Slopkit (Webkit)
  • Save file exploit for Artemis engine games (Lua Loader)
  • Save file exploit for Ren'Py engine games (YARPE)
  • Netflix exploit (Netflix-N-Hack)
  • Mast1c0re (PS2 emulator exploit)
  • BD-JB (Blu-ray Java exploit)
  • Vue After Free exploit
Either stay, or update to 11.00 and not above Recommended exploit is the web browser (Webkit), as seen with the Standard Jailbreak tutorial.

VueAfterFree and BD-JB are good alternative options to Webkit. However, VueAfterFree requires the PS4 to have a LAN connection, whereas BD-JB doesn't need any online connection, and Webkit exploits need at least temporary access to LAN or internet to cache the exploit website on your PS4's hard drive for offline use. This firmware also has access to using Netflix (with Netflix-N-Hack) and game save exploits (such as Lua Loader and Mast1c0re) to jailbreak the console, but these methods are more of a novelty to the end user due to this firmware range having access to Webkit/BD-JB/VueAfterFree.

These firmware versions (in addition to 11.02) can still use a Webkit-based jailbreak (through the CSSFontFace exploit, or on 11.00+, "Slopkit"), PPPwn, or BD-JB/Lua Loader/Netflix-N-Hack.

11.00 firmware is the last version that supports the PPPwn exploit, which requires tethering the PS4 to another computer with an Ethernet cable, but it generally has worse stability and success rate compared to the exploits which came after it, so it's recommened to use Webkit exploits and/or VueAfterFree on 10.00 to 11.00 firmware versions anyway.

11.02
  • Lapse
  • Netctrl/Poopsploit
Stay on current firmware
11.50 to 12.00
  • Slopkit (Webkit)
  • Save file exploit for Artemis engine games (Lua Loader)
  • Save file exploit for Ren'Py engine games (YARPE)
  • Netflix exploit (Netflix-N-Hack)
  • Mast1c0re (PS2 emulator exploit)
  • BD-JB (Blu-ray Java exploit)
  • Vue After Free exploit
Either stay, or update to 12.02 and not above Recommended exploit is the web browser (Webkit), as seen with the Standard Jailbreak tutorial.

VueAfterFree and BD-JB are good alternative options to Webkit. However, VueAfterFree requires the PS4 to have a LAN connection, whereas BD-JB doesn't need any online connection, and Webkit exploits need at least temporary access to LAN or internet to cache the exploit website on your PS4's hard drive for offline use. This firmware also has access to using Netflix (with Netflix-N-Hack) and game save exploits (such as Lua Loader and Mast1c0re) to jailbreak the console, but these methods are more of a novelty to the end user due to this firmware range having access to Webkit/BD-JB/VueAfterFree.

All of the games released on the PS4 which use the Artemis and Ren'Py engines should be exploitable, but not all have been thoroughly tested. There may be more games that use Lua scripts which could also be used for Lua exploits, but these are also untested and are only theoretical.

It is recommended not to update past 12.02 at this time, as the kernel exploit compatible with 12.5x versions isn't as consistent as the Lapse exploit. That being said, it may change in the future.

12.02 Stay on current firmware
12.50
  • Slopkit (Webkit)
  • BD-JB (Blu-ray Java exploit)
  • Vue After Free exploit
  • Netctrl/Poopsploit
  • Relapse (theoretical)
Recommended exploit is the web browser (Webkit), as seen with the Standard Jailbreak tutorial.

VueAfterFree and BD-JB are good alternative options to Webkit. However, VueAfterFree requires the PS4 to have a LAN connection, whereas BD-JB doesn't need any online connection, and Webkit exploits need at least temporary access to LAN or internet to cache the exploit website on your PS4's hard drive for offline use. The kernel vulnerability utilized by the Lapse exploit was patched starting with 12.50, so this firmware range can only utilize the Netctrl kernel exploit (nicknamed as "Poopsploit"). While the userland portion of the Lua, Yarpe, and Netflix exploits still work on firmware newer than 12.02, the "Poopsploit" kernel exploit isn't compatible with these due to the OS privilege it requires, which can only be accessed through Webkit, the PlayStation Vue application, the PS2 emulator, or BD-JB.

Access to BD-JB on 13.00 and newer currently requires using another jailbreak method (such as through Webkit or VueAfterFree) to copy a .jar file to the PS4's hard drive.

12.52
13.00
  • Slopkit (Webkit)
  • BD-JB with custom 00000.jar file in /system_ex/ (Blu-ray Java exploit)
  • Vue After Free exploit (Theoretical on 13.02 & 13.04)
13.02 and 13.04
  • Relapse
This firmware range has a Webkit exploit method available with the "Relapse" kernel exploit. The PlayStation Vue app was blocked by Sony starting with 13.50 firmware, so VueAfterFree will no longer be possible on this 13.50 or newer, but BD-JB will still be accessible if the Relapse exploit is ported to it. Netflix-N-Hack & the existing game save exploits may possibly work with the new kernel exploit, but this hasn't been demonstrated.
13.50
  • Slopkit (Webkit)
  • BD-JB with custom 00000.jar file in /system_ex/ (Blu-ray Java exploit)
13.52
14.00 or higher
  • No public userland exploit exists for the recent/latest firmware.
  • No public kernel exploit exists for the recent/latest firmware.
Sell console, or stay. As there are no public kernel exploits past 14.00, you should either sell your console, or wait for one to come to your firmware.