TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A group of PlayStation security researchers has publicly released ‘Relapse,’ a two-stage exploit chain that works through the PS5 web browser on firmware versions 7.00 through 13.60. It combines a WebKit bug with a kernel use-after-free to gain kernel read/write access and load custom code. The release states it is intended for research only, and Sony has not commented.
A team of console security researchers has publicly released Relapse, an exploit chain that targets PlayStation 5 firmware versions 7.00 through 13.60 through the console’s web browser. The project, published on GitHub by developer ntfargo with credited contributions from several named researchers, chains a WebKit memory corruption bug with a kernel use-after-free to gain read/write access in the PS5 kernel and load unsigned code. The release expands the range of PS5 system versions for which public exploitation tooling exists.
According to the project’s GitHub repository, the exploit is triggered from the PS5 browser: users either point the console’s Primary DNS to 45.56.67.85 (described as recommended), run a local Python server via serve.py, or open the hosted page at the project’s GitHub Pages address. After a successful run, an ELF loader listens on port 9021, allowing custom payload files to be sent to the console. Default payloads are stored in the project’s payloads/ directory.
The repository describes the technical chain in two stages. The browser stage uses JavaScriptCore info leaks and what the authors call a structured clone object pool mismatch to corrupt a typed array. The kernel stage then combines an address leak with a race condition in aio_multi_wait — a use-after-free — to establish kernel read/write primitives.
The authors are candid about reliability limits: the WebKit stage may need several attempts and users should reload the page if the browser stalls, while the kernel stage may hang or panic the console, requiring a reboot before retrying. Credits list Sonic_Iso (kernel exploit), Jordy (WebKit exploit and kernel bug), ntfargo and ufm42 (exploit development), and Dr. Yenyen (testing), with additional acknowledgements including TheFlow, SlidyBat, Flatz, and others.
Impact on PS5 Homebrew and Security
The release matters for two audiences. For the homebrew and research community, Relapse provides a working, documented path to run unsigned code on PS5 consoles spanning a wide firmware range, including relatively recent system versions. The kernel read/write access it establishes is the foundation for further tooling such as debuggers, Linux loaders, or other custom software on supported consoles.
For Sony, a public exploit chain covering firmware up to 13.60 will likely accelerate a patch response, since browser-based entry points require no hardware modification and are easy for casual users to attempt. Sony has historically issued firmware updates to close publicly disclosed vulnerabilities, and users who want to keep access to this exploit would need to avoid updating. The repository’s own disclaimer warns that misuse carries risks including system instability, data loss, and account bans.
PS5 Exploitation Before Relapse
: “Public PS5 exploitation research has advanced in steps since the console launched in 2020, with earlier work by researchers such as TheFlow and others in the PlayStation security scene laying groundwork in WebKit and kernel bug classes. Relapse follows the familiar pattern of console exploits: a browser-side vulnerability is used to corrupt memory in the application that first parses untrusted content, after which a second bug escalates privileges into the kernel.
The project is published under an explicit educational and research disclaimer: it does not endorse piracy or unauthorized access, and its maintainers state the software is provided as-is, without warranty, with users assuming all risk. It is intended only for devices the user owns or is authorized to test.
“Supported firmware: 7.00 through 13.60.”
— Relapse-Exploit GitHub repository
Unverified Claims and Open Questions
Several points remain unconfirmed. The firmware range of 7.00 to 13.60 is stated only by the project’s own documentation; independent verification of which versions are reliably exploitable has not been established in this reporting. The repository does not state whether the bugs used are patched in the latest PS5 firmware, and it is not yet clear whether Sony will patch them or has already done so in an unreleased update.
The exploit’s real-world stability, the capabilities of the included payloads beyond the ELF loader, and whether the public DNS server (45.56.67.85) remains operational over time are also unknown. Sony has not publicly commented on the release, and no statement has been made about potential enforcement actions such as account bans for users who run it.
Expected Sony Patch and Community Follow-Up
The most likely near-term development is a Sony firmware update addressing the WebKit and kernel bugs once they are confirmed and prioritized, as has happened with prior public console exploits. Console owners on supported firmware who are interested in the exploit will face the usual trade-off between staying on an old system version for exploitation and updating for online features and new software.
In the community, expect follow-up work: additional payloads built for the port-9021 loader, reliability improvements from other developers, and documentation of which firmware versions actually work in practice. Any Sony response, patch notes, or enforcement actions would be the next confirmable developments to watch.
Key Questions
Which PS5 firmware versions does the Relapse exploit support?
According to the project’s GitHub repository, Relapse supports firmware 7.00 through 13.60. This range is stated by the developers and has not been independently verified in this reporting.
Does Relapse require a modified console or hardware?
No hardware modification is described. The exploit runs through the PS5’s built-in web browser, using either a DNS setting, a locally hosted Python server, or a hosted web page.
Is the exploit reliable?
The developers themselves warn it is not fully reliable: the WebKit stage may need several attempts, and the kernel stage may hang or panic the console, requiring a reboot before retrying.
What does the exploit actually do once it succeeds?
After a successful run, an ELF loader listens on port 9021, allowing custom payload files to be loaded onto the console. The kernel stage establishes kernel read/write access, which is the basis for running unsigned code.
Is using Relapse risky?
The project’s disclaimer states the software is provided as-is without warranty and that users assume risks including system instability, data loss, and account bans. The authors say it is intended for educational and security research on devices you own or are authorized to test only.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
