Y2JB is userland code execution using PS5 Youtube app
JavaScript
1,456
79 commits
updated Aug 2, 2026
Userland code execution using the PS5 YouTube app.
127.0.0.2 (leave Secondary DNS blank)Note: You may see a network/PSN connection error - this is expected and can be safely ignored. The console will still function normally for YouTube payload delivery.
Alternative: Instead of using 127.0.0.2, you can block PSN servers using your custom DNS server.
The DNS configuration is critical for Y2JB to function properly for two technical reasons:
Note: If you're using the backup file from the releases page, you can skip this section.
Y2JB requires a fake-activated account to run properly.
Important: If you have a legit PSN-activated account (officially registered through PlayStation Network), you cannot use it directly with Y2JB. You must create and use a separate fake-activated account instead.
To fake activate an account:
/user/download/PPSA01650
download0.dat from the releases page and send it using FTPY2JB_backup_1.6(4.03)Y2JB_backup_1.6(12.20)⚠️ WARNING: Restoring backup data WILL FACTORY RESET YOUR PS5. All data on your console will be erased.
⚠️ CRITICAL WARNING: Database corruption can result in the deletion of ALL installed FPKGs and savedata stored on your internal storage. Before proceeding with this section, backup your savedata using the PS5's built-in backup and restore feature in Settings to prevent data loss.
This script prevents the YouTube app from updating if you accidentally connect to the internet. Allowing updates can cause a softlock that prevents YouTube from launching (see next section for fix instructions).
Steps:
/system_data/priv/mms/appinfo.db from your PS5 using FTPappinfo.db in the same directory as appinfo_editor.pyappinfo.db and block YouTube updates:
python appinfo_editor.py
/system_data/priv/mms/appinfo.db with the modified versionThis issue typically occurs when you connect to the internet before setting the 127.0.0.2 DNS (most common with WiFi users).
Recovery steps:
Note: The Remote JS Server does not always use port 50000. While it typically defaults to port 50000, it may occasionally use a different port - this is normal behavior, not a bug.
You can send payloads using payload_sender.py (requires Python).
Usage:
python payload_sender.py <host> <file>
python payload_sender.py <host> <port> <file>
Examples:
python payload_sender.py 192.168.1.100 helloworld.js
python payload_sender.py 192.168.1.100 50000 helloworld.js
python payload_sender.py 192.168.1.100 9020 payload.bin
Firmware Compatibility: Only works up to firmware 10.01
After the Lapse payload succeeds, you need to send the HEN or other elf binary to port 9021. You can use any TCP payload sender such as:
netcatpayload_sender.pyExample:
python payload_sender.py 192.168.1.100 9021 hen.bin
This tool is provided as-is for research and development purposes only.
Use at your own risk.
The developers are not responsible for any damage, data loss, or consequences resulting from the use of this software.
JavaScript
95.0%
Python
5.0%
Y2JB is userland code execution using PS5 Youtube app
JavaScript
1,456
79 commits
updated Aug 2, 2026
Userland code execution using the PS5 YouTube app.
127.0.0.2 (leave Secondary DNS blank)Note: You may see a network/PSN connection error - this is expected and can be safely ignored. The console will still function normally for YouTube payload delivery.
Alternative: Instead of using 127.0.0.2, you can block PSN servers using your custom DNS server.
The DNS configuration is critical for Y2JB to function properly for two technical reasons:
Note: If you're using the backup file from the releases page, you can skip this section.
Y2JB requires a fake-activated account to run properly.
Important: If you have a legit PSN-activated account (officially registered through PlayStation Network), you cannot use it directly with Y2JB. You must create and use a separate fake-activated account instead.
To fake activate an account:
/user/download/PPSA01650
download0.dat from the releases page and send it using FTPY2JB_backup_1.6(4.03)Y2JB_backup_1.6(12.20)⚠️ WARNING: Restoring backup data WILL FACTORY RESET YOUR PS5. All data on your console will be erased.
⚠️ CRITICAL WARNING: Database corruption can result in the deletion of ALL installed FPKGs and savedata stored on your internal storage. Before proceeding with this section, backup your savedata using the PS5's built-in backup and restore feature in Settings to prevent data loss.
This script prevents the YouTube app from updating if you accidentally connect to the internet. Allowing updates can cause a softlock that prevents YouTube from launching (see next section for fix instructions).
Steps:
/system_data/priv/mms/appinfo.db from your PS5 using FTPappinfo.db in the same directory as appinfo_editor.pyappinfo.db and block YouTube updates:
python appinfo_editor.py
/system_data/priv/mms/appinfo.db with the modified versionThis issue typically occurs when you connect to the internet before setting the 127.0.0.2 DNS (most common with WiFi users).
Recovery steps:
Note: The Remote JS Server does not always use port 50000. While it typically defaults to port 50000, it may occasionally use a different port - this is normal behavior, not a bug.
You can send payloads using payload_sender.py (requires Python).
Usage:
python payload_sender.py <host> <file>
python payload_sender.py <host> <port> <file>
Examples:
python payload_sender.py 192.168.1.100 helloworld.js
python payload_sender.py 192.168.1.100 50000 helloworld.js
python payload_sender.py 192.168.1.100 9020 payload.bin
Firmware Compatibility: Only works up to firmware 10.01
After the Lapse payload succeeds, you need to send the HEN or other elf binary to port 9021. You can use any TCP payload sender such as:
netcatpayload_sender.pyExample:
python payload_sender.py 192.168.1.100 9021 hen.bin
This tool is provided as-is for research and development purposes only.
Use at your own risk.
The developers are not responsible for any damage, data loss, or consequences resulting from the use of this software.
JavaScript
95.0%
Python
5.0%