TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A publicly released exploit chain called Relapse targets PlayStation 5 firmware versions 7.00 through 13.60, chaining a WebKit bug with a kernel race condition to gain kernel read/write. It is intended for security research, not piracy, and Sony has not yet responded publicly.
A group of console security researchers has publicly released “Relapse,” an exploit chain for the PlayStation 5 that works on firmware versions 7.00 through 13.60, according to the project’s GitHub repository. The chain combines a browser-based WebKit exploit with a kernel exploit to establish kernel read/write access on the console, and is explicitly framed by its authors as intended for educational and security research purposes only.
The exploit, published at github.com/ntfargo/Relapse-Exploit, targets a wide range of PS5 system software: every major firmware from 7.00 to 13.60, according to the repository’s documentation. Rather than requiring a USB or hardware modification, the chain begins in the PS5’s web browser: users point the console’s network settings to a primary DNS of 45.56.67.85 (described as recommended by the maintainers) or run a local Python server, then open the hosted exploit page on the console itself.
According to the project’s technical notes, the exploit proceeds in two stages. The browser stage uses JavaScriptCore information leaks and a structured clone object pool mismatch to corrupt a typed array. The kernel stage then combines an address leak with a race condition in aio_multi_wait — a use-after-free — to establish kernel read and write access. After a successful run, an ELF loader listens on port 9021, allowing custom payloads stored in the repository’s payloads directory to be delivered to the console.
The maintainers caution that the exploit is not fully reliable. The WebKit stage “may need several attempts,” and users are told to reload the page if the browser stalls. The kernel stage “may hang or panic the console,” requiring a reboot before retrying. The repository’s disclaimer states the project “does not endorse piracy, unauthorized access, or misuse of commercial devices” and warns that use carries risks including system instability, data loss, and account bans. Credits listed on the page attribute the kernel exploit to Sonic_Iso, the WebKit exploit and kernel bug to Jordy, and exploit development to ntfargo and ufm42, with testing by Dr. Yenyen and assistance from several other known console-hacking community figures, including TheFlow and Sleirsgoevy.
What Relapse Means for PS5 Security
The breadth of supported firmware is what makes the release notable: covering versions 7.00 through 13.60 means a large share of PS5 consoles in circulation could theoretically be affected, unless owners have updated to a newer system software version. For security researchers, a documented kernel read/write primitive is the foundation for deeper analysis of the console’s operating system, homebrew development, and the study of mitigations Sony has in place.
The release also carries familiar industry tensions. Tools like this historically enable homebrew software and research, but can also be adapted for piracy and cheating, which is why the maintainers included an explicit disclaimer against unauthorized use. Sony has historically responded to such releases with firmware updates that patch the underlying bugs, and users running the exploit risk enforcement against their PlayStation Network accounts — a risk the project itself acknowledges.
Console Hacking’s Public Release Tradition
Public exploit releases for PlayStation hardware follow a long-established pattern in the console security research community, where findings are documented on GitHub and credited to named researchers. Several people credited on the Relapse repository — including TheFlow and Sleirsgoevy — are known for prior PlayStation research on earlier firmware generations. Kernel-level access on a locked-down console like the PS5 is a significant technical milestone because the system is designed to prevent unsigned code from running.
The two-stage structure of Relapse — a browser exploit to gain code execution in WebKit, followed by a privilege escalation into the kernel via a race condition — mirrors the architecture of many past console and mobile exploits, where a rendering-engine bug is paired with a separate kernel bug to escalate access.
“The kernel exploit may hang or panic the console, so reboot before trying again if that happens.”
— Relapse-Exploit GitHub repository, stability notes
What Is Not Yet Known
Sony has not publicly commented on the release, and it is unclear whether the affected bugs — the WebKit issue and the aio_multi_wait use-after-free — are already patched in firmware versions newer than 13.60. The repository does not state when the vulnerabilities were reported to Sony, or whether a coordinated disclosure period elapsed before publication.
It is also unknown how widely the exploit has been used since release, whether Sony will take action against accounts or consoles that connect to the exploit’s DNS server, and how stable the chain is across all listed firmware versions in practice, since the maintainers themselves note the browser and kernel stages can fail. Independent verification of the exploit’s claims by third-party researchers had not been documented at the time of writing.
Sony’s Likely Patch Response
The most probable next development is a PlayStation 5 system software update from Sony addressing the underlying WebKit and kernel vulnerabilities, as the company has done after previous public exploit releases. Owners who wish to keep access to online services would typically be required to install such an update.
For the research community, watch for independent reproductions of the exploit, follow-up analysis of the aio_multi_wait bug class, and any community-developed payloads built on the released ELF loader. Sony’s response — or silence — on the specific firmware versions affected will clarify how much of the install base remains exposed.
Key Questions
Which PS5 firmware versions does the Relapse exploit affect?
According to the project’s GitHub repository, the exploit chain supports firmware versions 7.00 through 13.60. Consoles running newer firmware are not listed as supported.
What does the exploit actually give researchers?
The chain gains execution through the PS5’s WebKit browser and then uses a kernel race condition to achieve kernel read/write access. After a successful run, an ELF loader listens on port 9021 so custom payloads can be run on the console.
Is using the Relapse exploit legal or safe?
The maintainers state the project is for educational and security research purposes only and warn of risks including system instability, data loss, and account bans. Anyone considering use should restrict it to devices they own and check applicable local laws.
Does the exploit work every time?
No. The documentation says the WebKit stage “may need several attempts,” and the kernel stage may hang or panic the console, requiring a reboot before retrying.
Has Sony responded or released a patch?
Sony has not publicly commented on the release as of this report, and it is unclear whether firmware versions above 13.60 already patch the underlying bugs. A future system update is the most likely response based on the company’s past handling of similar releases.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
