# WebKit CSSFontFace on PlayStation: an exploit chain published as research

> This repository publishes a use-after-free exploit in WebKit's CSSFontFace handling affecting the PlayStation 4 and 5 browsers, together with a kernel exploit path on older PS4 firmware and a dated technical writeup. Its version tables draw careful lines between where the bug exists, where it is exploitable, and where this chain actually works, and its own limitations section documents why current firmware is out of reach.

**ntfargo/CSSFontFace-Exploit** — WebKit CSSFontFace UAF exploit for PlayStation 4/5

- Repository: https://github.com/ntfargo/CSSFontFace-Exploit
- Stars: 325 · Forks: 87
- Language: JavaScript
- License: MIT
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/ntfargo-cssfontface-exploit

## Three tables that separate research from hype

The first thing the repository does right is refuse to conflate three different claims. A vulnerability-scope table states where the bug exists: PlayStation 4 firmware 6.00 through 13.52, and PlayStation 5 firmware 1.00 through 13.40. A separate exploitable-in table narrows that to where the bug can actually be turned into an attack: PlayStation 4 from 6.00 to 11.02, PlayStation 5 from 1.00 to 8.60. A third table states what this repository itself supports: the CSSFontFace chain on PlayStation 4 from 6.00 to 11.02, a kernel exploit from 7.00 to 11.02, and nothing at all on PlayStation 5.

Those are three honest distinctions that exploit marketing usually flattens. A bug being present is not a bug being weaponizable, and a weaponizable bug is not a finished chain, and the gap between the tables is where the engineering actually lives. The PlayStation 5 row carries an asterisk worth reading: exploitation is possible there only if address-space randomization can be defeated, through a heap-shaping trick or a separate leak bug, with the expected vtable pointer recovered before the native crash path completes.

For a security artifact, precision about its own boundaries is the strongest available signal of credibility, and this repository leads with it.

## The bug, and the primitive it bought

The vulnerability class is a use-after-free in WebKit's handling of CSS font faces, the browser-side machinery that loads and applies styled fonts. The repository's limitations section names the specific capability the bug yielded: a read and write primitive built on the font feature settings path, the internal state a page manipulates when it asks for fonts with particular typographic features.

That primitive's death is documented with equal specificity. Newer WebKit releases on PlayStation 4, from the 11.5x series onward, and on PlayStation 5, from 9.00 onward, redesigned how CSSFontFace properties are got and set, introducing a new internal connection structure in place of the old property storage. With that redesign, the feature-settings read and write path this chain depends on simply no longer exists in a usable form, which is why the supported ranges stop where they do.

On PlayStation 5 the obstacle is architectural rather than merely structural: vtable checks and WebKit's address-space layout randomization prevent this chain from working at all unless a separate randomization defeat and vtable recovery can be found. The writeup published alongside the repository walks through the mechanics; the README's job is to state the boundaries, and it does.

## The chain, and where it stops

What the repository ships is an entry point plus a slot. The WebKit exploit gets code execution in the browser context on the supported PlayStation 4 range; a kernel exploit covers firmware 7.00 through 11.02; and the payload itself is deliberately not included. The README instructs the user to place their own payload, homebrew enabler or otherwise, in the public source directory under a fixed file name.

That payload slot is the honest archaeology of the console homebrew scene: the research contributes the unlicensed-execution machinery, and what anyone runs with it is their own affair, which is also exactly where the legal weight lands. Running unsigned code on a PlayStation breaches the platform's terms of service, and depending on jurisdiction and purpose, most plainly piracy, it crosses into unlawful territory; the repository contributes a disclosure record, not legal cover, and offers no pretence otherwise.

On PlayStation 5 the chain stops at the browser: the repository's own table lists no supported kernel exploitation, marking the columns not applicable. The distance between the two consoles in the tables is the distance a decade of console hardening actually bought.

## A lineage, cited like one

The references section behaves like a bibliography rather than a shout-out list. Hacking the PS4, CTurt's foundational 2015 writeup, is credited as the origin of this line of work. A 2022 PlayStation 5 WebKit execution repository is credited for earlier contributions. The collaborators are named with their actual roles: one researcher for bug research and the full chain, the repository's author for bug research, the writeup and exploit development, a third for testing.

That citation habit situates the artifact in the long tradition of console browser exploitation, where the shipped web browser has been the perennial externally-reachable surface. The PlayStation's browser runs the same engine as consumer WebKit, which means a font-handling bug studied here is adjacent to bugs that matter everywhere WebKit ships, and the writeup's audience is as much browser-security engineers as console enthusiasts.

The technical writeup, hosted on the author's site under a dated blog entry, is the substance of the disclosure: the repository carries the tables, the payload slot and a serving harness, and the prose carries the reasoning.

## The artifact itself, minimal by design

The repository tree is five entries: a licence, the README, a host script, a locally scoped certificate file, and a public directory for the served content and the payload slot. The hosting arrangement is the console-scene standard: the exploit page is served over HTTPS from the local machine, with the self-signed certificate covering the localhost name, because the console's browser will not load the page over plain HTTP from an arbitrary origin.

There are no published releases, no build system, and no documented commands; the README is a scope document, not a manual. The licence is MIT, the last push was on 2026-07-27, and the whole thing reads as the companion code to a published writeup rather than a product.

That minimalism is consistent with the disclosure framing. Nothing here optimizes for distribution or ease; it optimizes for verifiability, which is the correct priority for security research and the wrong one for anything else.

## Who should read this, and the lines around it

The genuine audience is narrow and legitimate: browser-security researchers studying use-after-free patterns in font handling, engineers interested in how property-storage redesigns retire exploitation primitives, and historians of the console-security scene tracing the CTurt lineage forward. For them the value is the version matrices and the limitations section, which together document not just an exploit but the patch response that ended it.

For everyone else, the honest review position is that the directly actionable content is confined to firmware generations that current consoles have long left behind, and that the writeup is more instructive than the code. The platform's terms forbid what the payload slot implies, and the lawful uses of decade-old console firmware research are research itself.

The alternatives to this repository are its own references: the linked writeup explains the bug in prose without any tooling, and the cited foundational articles carry the tradition. What this artifact adds over reading alone is the reproducible boundary, tables you can check against a firmware changelog, and a chain whose supported range is stated narrowly enough to be falsified. In vulnerability research, that narrowness is the compliment.

## Conclusion

This repository fits browser-security researchers and console-security historians who want a published, honestly bounded WebKit use-after-free artifact: three distinct version matrices, a named primitive, a documented patch response, and a cited lineage. It does not fit anyone on current firmware, where the property-storage redesign retired the primitive, or anyone seeking legal cover, since running unsigned console code breaches platform terms and the payload slot's uses range from lawful research to plainly unlawful piracy. Verify first: the writeup behind the repository for the actual mechanics, the supported ranges against the firmware you care about, and your jurisdiction's rules before touching anything. The licence is MIT, and the last push was on 2026-07-27.

## FAQ

### Which PlayStation firmware versions does the CSSFontFace exploit affect?

Per the repository's tables, the vulnerability is present on PlayStation 4 firmware 6.00 to 13.52 and PlayStation 5 firmware 1.00 to 13.40, but it is exploitable only on PlayStation 4 up to 11.02 and PlayStation 5 up to 8.60, and the repository's own chain supports PlayStation 4 only, with kernel exploitation from 7.00 to 11.02.

### Why does the exploit fail on current firmware?

Newer WebKit redesigned CSSFontFace property handling, introducing a new internal connection structure that retired the feature-settings read and write primitive the chain depends on. On PlayStation 5, vtable checks and address-space layout randomization additionally block the chain unless a separate randomization defeat exists.

### Is running this against a console legal?

The repository offers no legal guidance, and none should be inferred. Running unsigned code breaches the platform's terms of service, and legality varies by jurisdiction and purpose, with piracy unlawful everywhere. The publishers frame the artifact as vulnerability research accompanied by a public writeup.

## Sources

- [Issues](https://github.com/ntfargo/CSSFontFace-Exploit/issues)
- [License: MIT](https://github.com/ntfargo/CSSFontFace-Exploit/blob/main/LICENSE)
- [ntfargo/CSSFontFace-Exploit on GitHub](https://github.com/ntfargo/CSSFontFace-Exploit)
- [README](https://github.com/ntfargo/CSSFontFace-Exploit/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ntfargo-cssfontface-exploit
