PS5 Relapse Exploit
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

The Relapse Exploit project’s GitHub page describes an exploit chain for PS5 firmware versions 7.00 through 13.60. Its maintainers warn that attempts may require retries and that the kernel stage can hang or panic a console; the source does not independently verify success across every listed version.

The PS5 Relapse Exploit project lists Sony console firmware versions 7.00 through 13.60 as supported and describes a browser-to-kernel exploit chain. The GitHub page warns that the process may take repeated attempts and that the kernel stage can hang or panic the console, making the project relevant to owners and security researchers weighing the risks of testing it.

The project instructions describe setting a primary DNS address in the PS5 network settings, then opening the project’s web page on the console or running its server locally. The page says default payloads are stored in the project’s payloads directory and that, after a successful run, an ELF loader listens on port 9021. These are the maintainers’ instructions; the supplied material does not include independent testing or confirmation that every step works on every listed firmware version.

The project describes two technical stages. Its browser stage uses JavaScriptCore information leaks and a structured-clone object-pool mismatch to corrupt a typed array. The kernel stage combines an address leak with an aio_multi_wait use-after-free race to establish kernel read and write access, according to the GitHub description.

Stability is a stated limitation. The maintainers say the WebKit stage may take several attempts and advise reloading if the browser stalls. They also warn that a kernel-stage attempt can hang or panic the console, and recommend rebooting before another attempt after such a failure. The project is provided without warranty; its disclaimer cites possible system instability, data loss and account bans.

At a glance
reportWhen: Current status based on the supplied Gi…
The developmentA GitHub project page for the PS5 Relapse Exploit lists support for firmware 7.00 through 13.60 and details reported stability risks.
Top Steam deals right now
Persona 3 Reload-70%$17.99
Persona 5 Royal-70%$17.99
The Witcher 3: Wild Hunt — Remastered-50%$24.99
DARK SOULS III Deluxe Edition-50%$42.49
DARK SOULS™: REMASTERED-50%$19.99
Dune: Awakening-50%$24.99
DARK SOULS™ II: Scholar of the First Sin-50%$19.99
The Last of Us™ Part II Remastered-33%$33.49
Live · Steam store (current discounts)

Risks for PS5 Owners

The listed firmware range and described kernel access make this project relevant to console security research, while the stated failure modes matter to anyone considering a test. A hang or panic can interrupt use of the console, and the project’s own disclaimer names potential data loss and account bans. The supplied material does not quantify how often these outcomes occur.

The page says the software is intended for educational and security research purposes, and instructs users to test only devices they own or are authorized to assess. That framing matters because the described capabilities could be misused. The project’s disclaimer does not establish that use is lawful in every location or circumstance; users are directed to comply with applicable laws and regulations.

Amazon

Top picks for "relapse exploit"

As an affiliate, we earn on qualifying purchases.

How the Exploit Chain Works

The project presents Relapse as a chain rather than a single browser bug: a WebKit browser stage is followed by a kernel stage. In the project’s account, the first stage corrupts a typed array using JavaScriptCore information leaks and an object-pool mismatch, while the second uses a race involving aio_multi_wait to obtain kernel read and write access.

The GitHub page credits ntfargo, ufm42, Sonic_Iso, Jordy, Dr. Yenyen, TheFlow, SlidyBat, Flatz, cow, nhk, bollarz, Sleirsgoevy, EchoStretch and EarthOnion. The supplied source gives no release date, detailed version-by-version test results or independent assessment, so it supports describing what the project claims and instructs, but not treating those claims as externally verified findings.

“The kernel exploit may hang or panic the console.”

— Relapse Exploit project maintainers

Verification and Failure Rates

The supplied project description lists firmware 7.00 through 13.60, but it does not provide independent verification or results for each version. It is also unclear how often users encounter browser stalls, kernel hangs or panics, or whether the described outcomes vary by console configuration. The material gives no release date or information about later changes to the project.

Further Testing and Project Updates

The source material identifies no scheduled release, external review or next milestone. Readers seeking a current status would need to consult the project’s GitHub page for any subsequent changes to the supported firmware range, instructions or stability notes. Any assessment of reliability across versions would require evidence beyond the project description supplied here.

Key Questions

Which PS5 firmware versions does the project list as supported?

The GitHub description lists firmware 7.00 through 13.60. The supplied material does not independently verify the claim for each version.

What does the project say can go wrong?

It says the WebKit browser stage may need several attempts and that the kernel stage may hang or panic the console. Its disclaimer also names possible data loss and account bans.

What does the exploit chain involve?

According to the project page, the browser stage uses JavaScriptCore information leaks and a structured-clone object-pool mismatch to corrupt a typed array. The kernel stage uses an address leak and an aio_multi_wait use-after-free race to establish kernel read and write access.

Does the source prove the exploit works on every listed firmware?

No. The page lists a supported range, but the supplied source provides no independent testing or version-by-version verification.

What use does the project say is intended?

The maintainers describe it as intended for educational and security research. They say users should test only devices they own or are authorized to assess and comply with applicable laws.

Source: hn

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

What Browser Security Means in a SaaS World

Just how secure is your browser in a SaaS world? Discover essential strategies to protect your cloud access and stay ahead of threats.

What Business Email Compromise Looks Like in Practice

AIThis post was created with the assistance of artificial intelligence (AI).In practice,…

The Bottleneck Moved: Inside Anthropic’s Expansion of Project Glasswing

Anthropic’s Project Glasswing is expanding to over 150 organizations, shifting focus from finding vulnerabilities to fixing them, particularly in critical infrastructure.

Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording

Two hackers, brothers Muneeb and Sohaib Akhter, pleads guilty after their firing incident was recorded on Microsoft Teams, revealing their plot to destroy government databases.