Modders hint at potential kernel exploit hack for Xbox One consoles

xbawks.png

It's been a while since Microsoft released the Xbox One, and despite its age, there haven't been any reliable softmod methods to hack the console. Until now. A post started making the rounds, saying that a method for executing kernel level code on the Xbox One had been found. A list of instructions for preparing Xbox One systems to be hacked was also provided, with the process being as follows:

  1. Ensure your Xbox Live account Login-Type is configured as “No barriers” aka. auto-login with no password prompt
  2. Set your console as “Home Console” for this account
  3. Download the App Game Script
  4. Start the app (to ensure license is downloaded/cached)
  5. Take your console offline! To make extra sure it cannot reach the internet, set a manual primary DNS address of 127.0.0.1
  6. Get a device/microcontroller that can simulate a Keyboard (rubber ducky or similar) - otherwise you have to type a lot manually :D

This method appears to use a UWP app called Game Script on the Xbox One to execute the code, and was discovered by a user named carrot_c4k3. It seems as though the hack will require a lot of manual typing, unless you have a device that can simulate a keyboard, according to the preparation instructions. Reportedly, the latest firmware update for the Xbox One has already patched the exploit out, with the last exploitable firmware being 10.0.25398.4478.

:arrow: Source
:arrow: Video guide on how to prepare your system
:arrow: Proof of concept code
 
Micro$oft might already have patched it according to Wololo

https://wololo.net/2024/06/10/xbox-...-firmware-update-probably-patched-it-already/

Edit
According to the dev, exploit will also work on series-x and not just the X-Bone....but he says it will not enable Sailing the Seven Seas


And why it was patched damn big mouth folks broadcasting prequistes on youtube lol... Why couldn't the dev have been like the flow and had it all together actually doing something??? But then the xboxone like the ps3 was is very secure for a long time... But man impatient folks publish tidbits too early too anxious now everyone's outta luck lol 😆 😆 😆
 
Cuz if you got your game script revoked you could reupload it privately and you would have no choice too go online and download the privately uploaded copy of game script I assume
 
the person who gave me the appx says it works on windows and xbox here is the archive org page this may work in retail but why would anyone try to reupload it just to get there account banned 🤷‍♂️ https://archive.org/details/game-script
with that if I buy a brand new Xbox series X can I run the exploit or I would really have to had the app game script on my console before and no way to just run now without it???

If so, I wish there was a way to inject it into the console :(
 
with that if I buy a brand new Xbox series X can I run the exploit or I would really have to had the app game script on my console before and no way to just run now without it???

If so, I wish there was a way to inject it into the console :(
yeah the appx I provided should work but you need to have access to a UWP developer account ever sense the crackdown on emulators in retail I don't think game script is going too last long even if you privately upload it for yourself something similar too injecting would just too move game script app too a usb drive and put the drive into another console i have not tested this but it might work? I wonder if we upload game script under the game category to somewhat access the game os like switching app to game in dev mode idk if that will work either
 
Thank you for sharing 👌

I really hope that the way might be found for the app to be injected before the July firmware update 😌
 
Can someone with more expertise answer the question of whether or not this will work on an Xbox Series S console? I thought I had read that, but can't find anything that shows that.
 
Can someone with more expertise answer the question of whether or not this will work on an Xbox Series S console? I thought I had read that, but can't find anything that shows that.
Yes the game script also works on series s/x, but the app has already been taken down and patched in the June update by MS. So if you didn't get the app before, and update FW to a specific version, you're out of luck now. Its unknown yet if the dev has plans to support series s/x though, or what will come of this in the future. Tbh I personally would not risk getting a newer gen console banned, but old Xbox one I don't care about if console banned.
 
Last edited by BigOnYa,
Is it possible that the game script application will be republished under a different name? the update has not yet been deployed to me
 
Is it possible that the game script application will be republished under a different name? the update has not yet been deployed to me
Of course its possible, but if not really soon, there will be the June fw update being pushed to you, which will take out the possibility.
 
Noice, I got that same clear case for a RGH3 slim, yours looks sharp.
Thanks :) I can't take all the credit this guy built it for me I only just told him what I wanted. He had his own store selling hacked x360's back when ppl were buying them like hot cakes. Glad he kept his youtube channel almost teared up with the nostalgic moments.
I also have a Falcon model with a flashed disc drive to play burned games.
 
Of course its possible, but if not really soon, there will be the June fw update being pushed to you, which will take out the possibility.
no, 4908 appears to still be vulnerable. if you're on 4908 and have game script you should be good, but avoid any future updates.
https://nitter.poast.org/carrot_c4k3/status/1801299700659982614#m

June update 4908 seems to be volnerable according to the hacker's post. I actually updated my consoles to this version. I noticed that another small update (less than 100 mb) has shown up afterwards on Xbox One X, but I didn't risk installing it. Not sure what it was related to.
  • Xbox One X (4908) - It takes about 35 seconds to produce 1337 response in the Game Script. Please share your consoles, firmwares and timings :)
I assume the timing should be much shorter on the Xbox Series S/X consoles.
 
Last edited by ArgonUK,
  • Love
Reactions: BigOnYa

Site & Scene News

Popular threads in this forum