Techspot Xbox One Hacked: Voltage Glitch Exploit Breaks Years of Security
Article Content
- •Markus Gaasedelen demonstrated the 'Bliss' voltage glitch exploit at RE//verse 2026.
- •The exploit allows full control over the original Xbox One, deemed unpatchable.
- •Only the original Xbox One is affected; newer models remain secure.
At the RE//verse 2026 conference, security researcher Markus 'Doom' Gaasedelen demonstrated a hardware exploit named 'Bliss' that successfully compromised the Xbox One console, which had been considered unhackable since its release in 2013. The exploit utilizes a voltage glitching technique that manipulates the power supply during the boot process, allowing unauthorized code execution and access to the system's security processor. This method specifically targets the original Xbox One model, leaving subsequent models like the Xbox One S and Xbox Series unaffected. Gaasedelen's approach marks a significant breakthrough in console security, as it undermines the hardware-level defenses that Microsoft had established. The hack is deemed unpatchable, providing attackers with full control over the console, including the ability to run unsigned code and access encrypted data. Gaasedelen has a history of research in Xbox security, emphasizing that his work aims to preserve console functionality rather than promote piracy.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…