A Guide To PlayStation Bug Bounty Program: Unlocking the Secrets

Sony PlayStation 4 is one of the most widely used gaming consoles. The other major competitor is the Xbox One by Microsoft. Being a gaming console doesnโt mean that it is free from exploitable vulnerabilities. The recent rise of cyber attacks on different platforms has pushed Sony to roll out bug bounty programs.
Introduction of the Bug Bounty Program
Like many other companies, Sony also had a private bug bounty program exclusive to a few select security researchers. It all changed in June. On June 24th, Sony announced a public bug bounty program open to all in collaboration with HackerOne.

The bounties are restricted to reports that pertain to a few domains of the PlayStation Network and in the case of the PS4 system, it is valid only for those about the current or beta version of the system software. The program doesnโt accept social engineering attacks, DDoS attacks, or issues about game software among others. While Sony hasnโt mentioned any specific reasons to bring in such a change, they mentioned that theyโve understood the valuable role that the research community plays in enhancing security. It basically translates to Sony keeping an eye out for their security in light of the increasing number of cyberattacks.
Accepted Vulnerabilities
Sony has released a list of accepted vulnerabilities that are accepted for the bug bounty program. The domains that are in scope for vulnerabilities in regard to the PlayStation Network are:
- *.playstation.net
- *.sonyentertainmentnetwork.com
- *.api.PlayStation.com
- my.playstation.com
- store.playstation.com
- social.playstation.com
- transact.playstation.com
- wallets.api.playstation.com
If you have a look at the domains mentioned in this list, all these deal with the core aspects of the PlayStation Network. External links and ads to other sites arenโt included unless they interact with the domain. Sony accepts reports on the PlayStation 4 system, operating system, and accessories when it comes to the console. The vulnerabilities include
- Cross-Site Request Forgery (CSRF)
- Cross-site Scripting (XSS)
- Unauthorized Cross-Tenant Data Tampering or Access (for multi-tenant services)
- Insecure Direct Object References
- Injection Vulnerabilities
- Authentication Vulnerabilities
- Server-Side Code Execution
- Privilege Escalation
- Significant Security Misconfiguration (when not caused by user)
- Directory Traversal
- Information Disclosure
- Open Redirects
- Sony Product Vulnerabilities (specific to the Sony designed/controlled components of the product)
Read More: How To Create Strong Passwords
Out-of-Scope Vulnerabilities
Sony doesnโt accept vulnerabilities in any other Playstation Network domain other than the 8 ones that are mentioned. Extra information about open-source vulnerabilities that have been made public for less than 7 days is also not accepted. Sony also doesnโt accept social engineering attacks aimed at internal employees, physical attacks, scanner reports including any automated exploitation tool. Network vulnerabilities are exploited by DDoS attacks, clickjacking, and HTTP flags among others.
Rewards
Until this point, the average bounty offered is 400$ and the total payout last disclosed was 177,500$. Sony has promised up to 50,000$ for severe vulnerabilities dealing with the PS4 and 3000$ for those to do with the PlayStation Network. The highest disclosed bounty so far is for 10,000$ was one to do with the exploitation of the Webkit browser engine. The vulnerability had a severity score of 7-8.9.
Read More: All About Bug Bounty Hunting
Webkit Browser Engine Exploitation
The vulnerability was disclosed on July 6 by a popular developer Nguyen. He announced it on his Twitter handle @thefow0. The Webkit engine had an earlier vulnerability found on PS4 firmware version 6.20. The exploit is done by establishing an arbitrary read/write and an arbitrary object address leak in wkexploit.js. The attack is progressed by setting up a framework to run ROP chains in index.html.

This generates two hyperlinks by default to test ROP chains. This was fixed in 6.50 firmware. As per the information on Nguyenโs Twitter account, he announced that the new vulnerability exists on systems running firmware 7.02 or earlier. According to him, the kernel exploit works in tandem with a Webkit exploit which preexists on firmware 6.72 or older.
He also discovered a vulnerability in the firmware version 6.02 a few months ago. He says that this was caused by missing locks in the IPV6_2292PKTOPTIONS option of set sockopt, which allows the attackers to race and free the struct ip6_pktopts buffer, while it is being handled by ip6_setptopt. Being one of the top paid vulnerability disclosure programs open for all, this is a good arena for people with enough exposure. It is also a good way for beginners to earn some credibility, provided that they can find bugs.
Similarly, the Play Station 5 is launched, this year is also expected to follow suit by rolling out a similar program immediately after the launch. This translates into continuous opportunities for those familiar and well-knowledged in the inner workings of the console and their gaming network.
Interested to learn more about the various bug bounty programs and their top contributors? Follow our blog to keep yourself updated with the latest trends in cybersecurity.ย
Mobile Application Penetration Testing for Qatar Government Digital Services: NCSA-ย Alignedย Securityย Assuranceย
Key Takeaways: Mobile Application Penetration Testing Qatar must cover the app, device storage, APIs, authentication and third-party components. Qatarโs NCSA assurance environment combines the National Information Assurance (NIA) Standard, the National Information Security Compliance Framework (NISCF) and accredited security assessment services. OWASP MASVS defines mobile security controls, while MASTG supplies practical test methods for Android […]
Qatar Data Protection Law: Implementing PDPPL Data Subject Rights Processes for Businessesย
Key Takeaways: The Qatar Data Protection Law (Law No. 13 of 2016) for Personal Data Privacy Protection, grants individuals specific rights such as right to access, correct, erase, object, withdraw consent, and right to be notified of processing or inaccurate disclosure. Beyond having a privacy policy, businesses or controllers, under Article 11 of Personal Data […]
AI Governance for Indian Enterprises: Building Internal Controls Beforeย Keyย DPDPย Obligationsย Take Effectย
Key Takeaways: The DPDP Act does not contain AI-specific provisions. Its requirements, however, apply in situations when an AI system processes digital personal data within its territorial and material scope. India is working on building a broader governance framework around safety, accountability, transparency and trust via programs like the IndiaAI Mission. Indian organizations should inventory […]
Cloud Security Audit for UAE Government Cloud Migration: NCAP and Security Requirements
Key Takeaways: A cloud security audit UAE helps government entities identify security, governance, configuration, access, data-protection and resilience gaps, before and after shifting critical workloads to the cloud. UAE National Cloud Security Policy has defined cloud governance, data security, data sovereignty, IAM, incident management, resilience, portability and cloud operations requirements. The National Cyber Accreditation Program […]
Data Privacy Consulting UAEย โย Building a PDPL-Compliant Data Governance Program
Key Takeaways: PDPL compliance requires ongoing operational governance that goes beyond policies to demonstrate how personal data is collected, used, protected, transferred, retained, and deleted. Data mapping helps businesses move from reactive compliance to proactive risk management by establishing a comprehensive inventory of the data ecosystem, helping build a mature data privacy and governance program. […]
Saudi Arabia’s Critical Systems Controls: What CSP-Linked Enterprises Must Comply With in 2026
Key Takeaways: The Critical Systems Cybersecurity Controls (CSCC) are more applicable to critical systems than to all IT assets owned or operated by an organization. To be in full compliance or to remain in full compliance with CSCC, organizations must maintain continuous adherence to NCA ECC. CSCC has 32 core controls and 73 sub-controls across […]