PS5 Relapse Exploit: firmware 7.00–13.60 jailbreak goes public
Original: PS5 Relapse Exploit
Why This Matters
Broad firmware coverage (7.00–13.60) means the vast majority of active PS5 units are potentially affected.
A GitHub repository named Relapse-Exploit has published an exploit chain targeting PS5 firmware versions 7.00 through 13.60. The chain combines a WebKit JavaScript engine vulnerability with a kernel-level use-after-free race condition to achieve full kernel read/write access.
Developer ntfargo, along with more than a dozen credited contributors, released Relapse-Exploit publicly on GitHub. The exploit covers a wide range of PS5 firmware — from version 7.00 up to the current 13.60 — making it one of the broadest jailbreaks published for the platform to date.
The attack chain runs in two stages. First, a browser-based stage exploits a JSC (JavaScriptCore) information leak combined with a structured clone object pool mismatch to corrupt a TypeArray. The second stage leverages an address leak paired with an `aio_multi_wait` use-after-free race condition to gain kernel-level read and write access. Once exploited, an ELF loader listens on port 9021 for follow-up payloads.
Setup is straightforward: users either point the PS5's primary DNS to a hosted server at 45.56.67.85, or run a local Python server. The repository notes that the WebKit stage may require multiple attempts, and the kernel exploit can occasionally cause a system panic — standard caveats for this class of vulnerability. Credits include well-known PS scene researchers such as TheFlow, Flatz, and Sleirsgoevy. The repository carries an MIT license and a disclaimer framing the release as educational security research.