PS5: “Byepervisor” exploit files and presentation slides released

Screenshot by @Andrew2007__
Following his presentation of an exploit for the PS5 Hypervisor at the Hardwear.io infosec conference yesterday (or, specifically, 2 exploits), PlayStation hacker SpecterDev has now published the files for the hypervisor exploit, as well as the slides for the presentation.
For all compatible firmwares (2.xx/1.xx), the exploit includes Kernel dumping code and code to decrypt SELF (Encrypted ELF) files. Furthermore, those of you lucky enough to be on Firmware 2.50 exactly, should be able to enjoy the included HEN (Homebrew Enabler).
What is Byepervisor
The PS5 Hypervisor is a piece of middleware designed to protect the console’s Firmware, notably its kernel, from malicious attacks. The Hypervisor in particular enforces eXecute Only Memory (XOM) rules on the kernel, to avoid attackers from reading/writing critical parts of the system. It is a key component of the PS5’s security, and bypassing or hacking it has forever been considered an essential part of getting full control over the PS5 system.

Byepervisor is such an exploit for earlier versions of the PS5 Hypervisor, which works on Firmwares 2.xx and 1.xx. This is an exploit by SpecterDev, which the PlayStation hacker disclosed in October 2024.

From the readme:
PS5 hypervisor exploit for <= 2.xx firmware. Two vulnerabilities and exploit chains are contained in the repo, they are independent of each other and either can be used. One exploit is provided mainly just for preservation (
/_old_jump_table_exploit), only the primary exploit chain needs to be used (QA flags exploit).
Download and use Byepervisor
You can download the Byepervisor exploit source code at https://github.com/PS5Dev/Byepervisor
You should really build it yourself from the sources (if you can’t/won’t do that, I’ll be bold and say that this kind of tool, in its current state, is probably not for you), but Zecoxao has provided a compiled version here: https://qiwi.gg/file/5j5w6925-byepervisornologger (source)
The slides for SpecterDev’s presentation can also be found at https://github.com/PS5Dev/Byepervisor/blob/main/Byepervisor_%20Breaking%20PS5%20Hypervisor%20Security.pdf
Important notes (from the readme)
- Currently only 2.50 FW is supported for Homebrew Enabler (HEN), support for other firmware versions will be added at a later time.
- The exploit payload (byepervisor.elf) will need to be sent twice, once before suspending the system and again after resuming.
- You will have to put the system into rest mode manually yourself
- Kernel dump from QA flags exploit will not contain hypervisor’s .data region at the moment, if this is important for you, dump using the jump table exploit after porting or disable nested paging first (this is a TODO)
How to use (From the readme)
- Run the UMTX exploit chain in webkit or BD-J and run an ELF loader
- Send
byepervisor.elf - Put the system into rest mode
- Power system back on
- Send
byepervisor.elfagain (if you use John Tornblom’s ELF loader, the ELF loader should continue to accept payloads after resume, if not the UMTX exploit will need to be run again)
PS5 Byepervisor exploit – What’s next?
Although only 2.50 is supported right now for HEN, it is very likely that all firmwares 2.xx/1.xx will get HEN support in the days or weeks to come (work is already ongoing for that). That is obviously still a minority of users even for those among us interested in PS5 hacking, but there’s also hope that this will help discover more vulnerabilities down the line, including on higher Firmwares. Because Kernel dump/decryption is now relatively easy on those firmwares, PS5 Firmware decompilation will be happening more broadly, and this should lead to interesting discoveries for the scene.
Source: SpecterDev

With the Zeco’s compiled elf, does the hen already work on 2.50?
Well Well Well, now i can unbox my OG PS5 right out of its box for the first time (firmware 2.00)
I took mine out a couple of weeks ago – seems mine was on 3.2. Enjoyed using etaHEN for a while but it was a deal breaker that sub 4.x has no m.2 support. I am installing a bunch of stuff (including ps4 games) so I really wanted the extra space to ‘move’ ps4 games to it (I set it actually as the default install location). I DO have a 6TB external USB3 HD and that actually seems to work better for some games (that fail to run on internal or m.2…odd). HomeBrew store also doesn’t run on 3.2 or lower it seems. Of course I do this and a week later byepervisor is released. *Sigh* I still think I made the right call for the m.2 support (plus the firmware 4.x is already ancient but gives you the ability to run newer games I guess…though not many). Good luck!
does this mean day 1 ps5 pros are vulnerable?
I was adamant on buying because of all the $0ny *** and concord tax stuff, but if it is the case and we get HEN, then ill buy one.
Good luck finding one on 1/2.xx.
If you do find one it will be very expensive.
People are paying £1000+ for a used 4.5.
Just wait, as wololo stated and what i found most important is the fact decryption of kernel is now possible and even though it’s on low Firmware it will educate us on how the system works.
I think this will lead to a Cyb1k scenario where we can play higher SDK games decrypted on say 2.5 HV Hen.
I wonder if games will require a backport to run on 2.5….
Why does the screenshot indicate firmware support v1.x-5.x…….hmmmm
Screenshot up top shows PS5 UMTX Jailbreak (1.xx – 5.xx) – anyone notice that it shows support up to firmware 5.x there? lol
MOD why you not approve my comment? Is it negative or incorrect that screenshot shows up to 5.x firmware supported? I know he said sub 3.x firmware but the screenshot from their website RUNNING the exploit shows up to 5.x – Fair to mention for speculation…no?
Upto 5.xx for the UMTX chain part lol!
Its always been a chained exploit which requires several parts to be cracked, userland etc that ends as a jailbreak etc.
So yes UMTX upto 5.xx but thats just the webkit part to follow through to HV on 2.5…not 5.x
Spector is not working on a BDKB implementation which imo is good, if we can keep it like that it will be simpler.
Dang all my comments went through lol – At any rate – ty Techno1ogy – That makes sense that the webkit exploit works up to 5.x but the HV exploit supports sub 3.x. *cheers*