|
|
#1 | |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 15
Karma: 2354
Join Date: Sep 2025
Device: Kindle
|
5.18.6 JB for PW5/PW5SE/KT5
This is a (poorly) adapted version of the Chromium bug CVE-2020-16040 for the Kindle Browser. Hopefully it can serve as a more convenient jailbreak for these models that doesn't require registration.
Guide: Quote:
Before 5.19.2, Amazon used incorrect command line flags in an attempt to disable Just-in-time (JIT) compilation and make the ancient version of Chromium more secure. The PW5/KT5 both run without the Chromium sandbox enabled, meaning no sandbox escape is needed to jailbreak the device. This will not work without a sandbox escape on most other Kindles. Credits: Rajvardhan Agarwal (r4j) - Original CVE-2020-16040 POC HackerDude - jb.sh script Last edited by hhhhhhhhh; 03-02-2026 at 03:15 PM. Reason: penguins took down the pages.dev |
|
|
|
|
|
|
#2 |
|
Junior Member
![]() Posts: 3
Karma: 10
Join Date: Mar 2026
Device: PW5-SE
|
Think this could work with other models? Willing to test it on my KPW11SE tonight or is that a no-go? Miffed that an automatic update before I could stop it ruined my chances of jailbreaking...
|
|
|
|
|
|
#3 |
|
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,170
Karma: 12345678
Join Date: Feb 2010
Location: Serbia
Device: Kindle PW5, Kobo Libra 2, Kindle PW1
|
"KPW11SE" is just "SE" of PW5 ( = what we here use as a name for device that Amazon calls "Kindle Paperwhite 11th Generation"). Sooo, that would be a "PW5SE" mentioned in the title. So yes, it should work.
|
|
|
|
|
|
#4 | |
|
Junior Member
![]() Posts: 3
Karma: 10
Join Date: Mar 2026
Device: PW5-SE
|
Quote:
|
|
|
|
|
|
|
#5 |
|
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 5,972
Karma: 106592599
Join Date: Apr 2011
Device: pb360
|
Have a look at this for kindle nicknames:
https://wiki.mobileread.com/wiki/Kindle_Serial_Numbers |
|
|
|
|
|
#6 |
|
Junior Member
![]() Posts: 3
Karma: 10
Join Date: Mar 2026
Device: PW5-SE
|
Log of how it went:
- Opened on Airplane, ensured firmware version 5.18.6 - Filled up the space, reads 0.00 GB of 27.30 GB - Opened the website. Big picture of Jeff Bezos' face with an "L" on his forehead, tells me to press the L to jailbreak - Pressed a few times, doesn't seem to do anything. Paused to type this and it goes back to the main menu saying"Application Error. The selected application could not be started. Please try again." - Trying again. - Looked like nothing happened at first but got text overlay on screen showing nosb jailbreak and a "finished jailbreak, please install HOTFIX now" message!!!!!! - Installing hotfix: - Put back in airplane mode - Downloaded hotfix file - Plugged in USB and deleted a single 10MB space-filling file to allow enough space for hotfix - Dropped into root - No other .bin files... - Ejected, unplugged... - On Kindle navigated to "Update your Kindle" and accepted update - IT'S WORKING! - Couple minutes later back to home screen with "Run Hotfix" book. Tapped and run! @hhhhhhhhh a massive thank you to you and everyone else involved, fantastic effort! |
|
|
|
|
|
#7 |
|
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 600
Karma: 4016635
Join Date: Jul 2023
Device: Scribe 2022, OA2, PRS-350
|
Be sure to install and activate an OTA blocker before putting it back online, esp. if you've freed up space.
|
|
|
|
|
|
#8 |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 15
Karma: 2354
Join Date: Sep 2025
Device: Kindle
|
I was made aware of a Reddit post that falsely claimed Nosebleed contained a backdoor. The author of the post has since deleted it and I believe they likely used an LLM to "reverse engineer" the jailbreak.
HackerDude has already reviewed the code here and confirmed it does not contain a backdoor: https://github.com/KindleModding/kin....io/issues/130 None of the code is obfuscated and you're free to review it yourself. Obviously be careful when installing any Kindle mods from strangers, but take information with a pinch of salt. |
|
|
|
|
|
#9 |
|
Junior Member
![]() Posts: 8
Karma: 10
Join Date: Jul 2024
Device: Kindle Paperwhite 11
|
Thanks a lot, worked like a charm on my PW5SE! After amazon pushed a UI update that broke the way I was using dictionaries, I decided to jailbreak and go with Koreader, but discovered that 5.18.6 I was on was unbreakable. So, I stayed in airplane mode ever since waiting for a new exploit.
Steps that I took. 1. Unpacked kindle_files.zip to the kindle storage root. 2. Filled memory until it was 0 bites free. Used dd for this to first create a 10M file (for Update_hotfix_universal.bin later) then filled the rest with 4095M blobs (max that fat32 supports) and one smaller blob to fill the remainder. 3. Turned on WiFi, opened https://kindlemodding.org/nosb in the browser and pressed "L". The browser crashed with an error, and after a bit I got text on top of the UI saying that jailbreak was successful and prompting me to install the hotfix. 4. Installed the hotfix after removing the 10M blob (that gave enough room on the storage for it). 5. Installed KUAL and disabled OTA per https://kindlemodding.org/jailbreaki...sable-ota.html 6. Freed up the storage from those dd blobs 7. Done. Now I could finally switch to Koreader |
|
|
|
|
|
#10 |
|
Weirdo
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,063
Karma: 12502580
Join Date: Nov 2019
Location: Wuppertal, Germany
Device: Kobo Sage, Kobo Libra 2, reMarkable PaperPro
|
JB went well for my PW2022. Though some of the steps are scarily slow.
|
|
|
|
|
|
#11 |
|
Junior Member
![]() Posts: 1
Karma: 10
Join Date: Apr 2026
Device: KT5
|
The latest KT5 cannot be used
This method doesn't seem to work on my KT5 (version 2024). After entering the URL and clicking the "L" letter, the browser doesn't crash (the system version is 5..18.6)
|
|
|
|
|
|
#12 |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 15
Karma: 2354
Join Date: Sep 2025
Device: Kindle
|
|
|
|
|
![]() |
| Tags |
| jailbreak |
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| (KT5) How to develop apps like KUAL/Where to get the libraries to do it? | codersquare | Kindle Developer's Corner | 4 | 11-09-2025 06:26 AM |
| Some extensions not working on KT5 | Seroham | Kindle Developer's Corner | 10 | 04-28-2025 05:20 AM |
| Kindle KT5 fails to install hotfix after reset. | leadus | Kindle Developer's Corner | 2 | 01-12-2025 09:16 AM |
| Hardware [KT5] Web browser no longer accepts file:///mnt/us ? | hexhexhex | Kindle Developer's Corner | 1 | 06-12-2024 12:50 PM |
| KT5 Can't get screensavers to work | wholycow | Amazon Kindle | 2 | 01-02-2014 01:10 AM |