TL;DR
Get the latest gadgets delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A GitHub project called Relapse-Exploit describes an exploit chain for PlayStation 5 systems running firmware 7.00 through 13.60. Its maintainers say the browser and kernel stages can be unstable, and warn users about console crashes, data loss and possible account bans.
A GitHub project named Relapse-Exploit describes a browser and kernel exploit chain for PlayStation 5 consoles running firmware 7.00 through 13.60. The project documents a method that uses the console’s browser stage and a kernel bug, while warning that attempts may stall, crash or destabilize the system.
The project’s instructions describe a setup involving the console’s network settings and a locally hosted or web-hosted page. It lists 45.56.67.85 as the recommended primary DNS value, and says users can either run a local Python server or open the project’s hosted page on the PS5. The repository says default payloads are stored in its payloads/ directory after a successful run, and that an ELF loader then listens on port 9021.
According to the project, the browser stage uses JavaScriptCore information leaks and a mismatch involving a structured clone object pool to corrupt a typed array. The kernel stage combines an address leak with an aio_multi_wait use-after-free race to establish kernel read and write access. Those are the maintainers’ technical descriptions; the supplied material does not include independent validation or a detailed account of testing across each supported firmware release.
The repository credits Sonic_Iso with the kernel exploit, and Jordy with the WebKit exploit and kernel bug. It credits ntfargo and ufm42 with exploit development and Dr. Yenyen with testing, alongside several other contributors. The maintainers say the project is for educational and security research purposes and disclaim support for piracy or unauthorized access.
Risks for Supported PS5 Systems
The stated firmware range spans multiple PS5 software versions, making the project relevant to owners and security researchers tracking console security. If the documented chain works as described, it would show a path from a browser-stage flaw to kernel-level access on systems in that range. The source material does not establish how reliably it works, what practical capabilities it enables beyond kernel read and write access, or whether Sony has addressed the underlying issues in later software.
For console owners, the immediate point is the risk of instability. The repository says the browser may require repeated attempts and the kernel stage may hang or cause a panic. Its disclaimer also names possible data loss and account bans. These warnings make the project’s own usage notes material to readers evaluating the release, even though the supplied source does not quantify the likelihood of those outcomes.
The release also illustrates why exploit availability does not automatically mean a simple or dependable result for every device. The reported chain has separate browser and kernel stages, each of which may fail. Firmware support is stated as a range by the project, but the material provided does not show a device-by-device success rate or independent reproduction.
How the Exploit Chain Is Described
Relapse-Exploit is presented as a repository containing implementation files, usage guidance, payloads and contributor credits. Its description places the initial activity in the PS5 browser and says a later kernel stage is used to obtain kernel read and write access. This sequence is the project’s own account of its design, rather than an independent security assessment.
The instructions say WebKit may need several attempts and advise reloading if the browser stalls. They also say a kernel exploit attempt may hang or panic the console, and recommend rebooting before another attempt in that case. The supplied material does not give a release date, disclose how the project was coordinated with Sony, or describe a patch status. Those details are needed to place the release on a precise timeline and establish whether current systems remain affected.
“This project is intended for educational and security research purposes only.”
— Relapse-Exploit maintainers, in the repository disclaimer
Reliability and Patch Status
The supplied project material does not establish whether the exploit has been independently reproduced across every firmware version from 7.00 to 13.60. It also does not provide success rates, the date of the release, or evidence about whether Sony has patched the reported vulnerabilities. The practical capabilities available after a successful run are not fully specified in the material provided.
It is also unclear how often the described instability occurs or what circumstances could lead to data loss or account action. The project names these risks but provides no estimates. Readers should treat the firmware range and technical description as claims made by the repository unless corroborating testing or vendor information is available.
Evidence Needed to Confirm Scope
The next useful developments would be independent testing that records results by firmware version, along with a clearer release timeline and any response or patch information from Sony. Such evidence would help establish whether the stated support range reflects repeatable results and whether newer system software remains affected.
Until then, the repository’s own instructions and disclaimers are the available source for the project’s claimed scope and risks. They advise that the software is used only on devices a person owns or is authorized to test, and that users comply with applicable laws. The material does not promise a stable run or provide a confirmed outcome for any individual console.
Key Questions
Which PS5 firmware versions does Relapse-Exploit list as supported?
The project lists firmware 7.00 through 13.60. The supplied material does not provide independent test results for each version.
What does the project say the exploit chain does?
Its description says a browser-stage flaw is followed by a kernel stage that establishes kernel read and write access. That is the repository’s technical account, not independent confirmation.
Can using the exploit damage or disrupt a console?
The maintainers warn that the browser can stall and that the kernel stage may hang or panic the console. Their disclaimer also lists possible data loss and account bans, without estimating how likely those outcomes are.
Has Sony confirmed a fix?
No patch information or Sony statement appears in the supplied project material. The status of any fix is unclear from these sources.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
