PS5 Relapse Exploit
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A GitHub project called Relapse-Exploit describes a browser and kernel exploit chain for PlayStation 5 consoles running firmware 7.00 through 13.60. The project warns that attempts may fail or crash the console; the supplied material does not independently verify the firmware claims or describe testing results.

A GitHub project named Relapse-Exploit describes a browser and kernel exploit chain for PlayStation 5 consoles running firmware 7.00 through 13.60. The documentation says the chain can establish kernel read and write access, but also warns that the kernel stage may hang or crash a console; the supplied information does not independently confirm the project’s claims or establish how reliably it works.

The repository identifies two stages. It says the browser stage uses JavaScriptCore information leaks and a structured-clone object-pool mismatch to corrupt a typed array. The kernel stage, according to the project, combines an address leak with an aio_multi_wait use-after-free race to establish kernel read and write access. These are descriptions from the project itself, not independently verified findings in the material provided.

The documentation also describes a payload system and says an ELF loader listens on port 9021 after a successful run. It notes that the WebKit portion may take several attempts and that the browser can stall. For safety, this report does not reproduce the repository’s instructions for configuring a console or launching the exploit.

The maintainers list credits for ntfargo, ufm42, Sonic_Iso, Jordy, Dr. Yenyen, TheFlow, SlidyBat, Flatz, cow, nhk, bollarz, Sleirsgoevy, EchoStretch and EarthOnion. The project’s disclaimer describes the software as intended for education and security research, says it is provided without warranty, and warns of potential system instability, data loss and account bans.

At a glance
reportWhen: Current status: described in the projec…
The developmentThe Relapse-Exploit GitHub project documents a PS5 exploit chain and lists support for firmware 7.00 through 13.60.
Top Steam deals right now
Persona 5 Royal-70%$17.99
Persona 3 Reload-70%$17.99
The Witcher 3: Wild Hunt — Remastered-50%$24.99
DARK SOULS™: REMASTERED-50%$19.99
DARK SOULS III Deluxe Edition-50%$42.49
Dune: Awakening-50%$24.99
DARK SOULS™ II: Scholar of the First Sin-50%$19.99
The Last of Us™ Part II Remastered-33%$33.49
Live · Steam store (current discounts)

What Kernel Access Could Enable

If the project’s technical description is accurate, reaching kernel read and write access would represent a significant level of control over an affected console. That makes the claimed firmware range relevant to security researchers and PS5 owners tracking vulnerabilities. The repository information alone does not establish what applications or changes are possible, whether the access persists after a restart, or whether the exploit can be used consistently.

The practical risk is also clear in the maintainers’ own warning: attempts may hang or panic the console. A failed attempt could interrupt use or risk data, while the project separately identifies possible account bans. The material does not quantify those risks or say whether Sony has responded. Readers should treat the documentation as a technical project description, not a guarantee of a working or safe result.

Amazon

Top picks for "relapse exploit"

As an affiliate, we earn on qualifying purchases.

A Browser-to-Kernel Exploit Chain

Relapse-Exploit is presented as a chain that begins in the console’s browser environment and then seeks access at the kernel level. In the repository’s account, information leaks and a typed-array corruption issue form the browser portion; a race condition and address leak form the kernel portion. This brief context is sufficient to explain why the project describes two distinct stages, without implying that either has been independently reproduced.

The supplied source is the project’s GitHub documentation. It gives a supported firmware range of 7.00–13.60, but provides no release date in the material supplied, independent technical review, test sample, success rate or comparison with other exploits. Its caution that WebKit may require repeated attempts and that the kernel stage can hang or panic the device points to variable outcomes, rather than a guaranteed result.

““The kernel exploit may hang or panic the console.””

— Relapse-Exploit maintainers

Claims Await Independent Verification

The available source does not show an independent reproduction of the exploit, test results across the stated firmware range, or a measured success rate. It is also unclear how the project behaves across different console models, whether Sony has patched any part of the chain, and whether use affects console data or online account status in specific cases.

The repository’s firmware range and technical account should therefore be attributed to its maintainers. The supplied material does not establish that every listed firmware version is vulnerable in practice or that a successful run produces lasting access. No company response or security advisory was included.

Further Testing and Sony Response

The next useful developments would be independent verification of the reported chain, clearer testing details for each firmware version, and any response or security guidance from Sony. Updates to the repository could also clarify reliability, affected console configurations and whether the stated risks have been observed during testing.

Until those details are available, the project’s documentation is the primary source for its claims. Readers should distinguish its stated capabilities from verified outcomes and take account of the maintainers’ warnings about instability, data loss and account consequences.

Key Questions

Which PS5 firmware versions does the project list?

The repository lists firmware 7.00 through 13.60. The supplied material does not independently verify that range.

What does Relapse-Exploit claim to do?

Its documentation describes a browser and kernel exploit chain that, it says, can establish kernel read and write access. That capability is a project claim in the source provided.

Is the exploit described as reliable?

No success rate is given. The maintainers say the WebKit stage may take several attempts and warn that the kernel stage may hang or panic the console.

What risks do the maintainers identify?

The disclaimer names possible system instability, data loss and account bans. It says the software is provided without warranty.

Source: hn

EVERGREEN BESTSE

Evergreen bestsellers Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Is Invisible Watermarking The Key To Authenticating AI-Generated Media?

Anthropic’s Claude will add invisible watermarks to AI-generated text and images, aiding in content verification. Details on technology and rollout are pending.

Show HN: adamsreview – better multi-agent PR reviews for Claude Code

New tool ‘adamsreview’ offers multi-stage, parallel code review for Claude Code, outperforming existing solutions in bug detection and false positives.

Garry’s Mod Climbing The Steam Charts

Garry’s Mod has climbed to the top 5 on Steam’s most-played games, reaching a peak of over 29,000 concurrent players, signaling a significant rise in popularity.

Rogue One: The Andor Cut — On Fan Editing as Tonal Reverse-Engineering

A fan editor releases ‘Rogue One: The Andor Cut,’ reimagining the film with tonal elements from the Andor series, raising questions about creative re-interpretation.