source: KDSBest @ twitter.com] Since naehrwert posted an lv2 exploit I will do so too . I didn't manage to make it work on 4.21 so I just did on 4.20 The stack pointer points to lv2 and if we do a syscall, the syscall saves register to the stack HAHA. Btw. It just crashes the console for now, since I totally overwrite dump the lv2 or some memory addresses I don't know. Feel free to try around, adjust the address of the stackpointer and so on. If you managed to get the panic payload executed. Tell me!!! ^^