TL;DR
Get the latest gadgets delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
The Relapse-Exploit GitHub project describes a PlayStation 5 exploit chain for firmware versions 7.00 through 13.60. Its maintainers warn that attempts may stall the browser or cause the console to hang or panic; the material does not establish how reliably the exploit works across supported systems.
The public Relapse-Exploit project describes a browser and kernel exploit chain for PlayStation 5 systems running firmware 7.00 through 13.60. The project’s documentation outlines the exploit stages and warns of possible browser stalls, console hangs, or system panics, but does not provide independent verification of success across that firmware range.
The project’s GitHub page lists firmware 7.00 to 13.60 as supported and describes two broad stages: a browser component and a kernel component. According to the documentation, the browser stage uses JavaScriptCore information leaks and a structured-clone object-pool mismatch to corrupt a typed array. The kernel stage combines an address leak with an aio_multi_wait use-after-free race to establish kernel read and write access.
The documentation also describes what may happen during use. It says the WebKit stage may require several attempts and that the browser can stall. It warns that the kernel stage may hang or panic the console, and advises rebooting before another attempt if that occurs. The project says its default payloads are stored in a payloads directory after a successful run and that an ELF loader listens on port 9021. These are project instructions and claims, not independently tested results in the supplied material.
The repository credits ntfargo and a group of contributors, including ufm42, Sonic_Iso, Jordy, Dr. Yenyen, TheFlow, SlidyBat, Flatz, and others. Its disclaimer says the software is provided without warranty and that use may carry risks including system instability, data loss, and account bans. The maintainers describe the project as intended for education and security research, and say users should test only devices they own or are authorized to examine.
What Kernel Access Could Enable
The project matters to PS5 owners and security researchers because the described chain reaches kernel read and write access, a level of access beyond a browser-only flaw. Such access can be relevant to research into console security and system behavior. The repository’s description alone does not establish what practical capabilities are available, how stable they are, or whether they work consistently on retail consoles.
For users, the documented failure modes are a direct concern. A browser stall may interrupt an attempt, while a kernel-stage hang or panic may require a reboot. The project also names possible data loss and account bans among the risks. It does not quantify how often these outcomes occur or specify which conditions could lead to an account penalty, so those warnings should be read as stated risks rather than measured probabilities.
Two Stages in the Exploit Chain
The project describes a browser entry point followed by a kernel stage. In its account, the first stage relies on JavaScriptCore information leaks and a structured-clone object-pool mismatch that corrupts a typed array. The next stage uses an address leak and an aio_multi_wait use-after-free race to establish kernel read and write access. This description explains the claimed technical path, but the supplied source includes no independent analysis or test results to assess it.
The documentation lists a broad firmware span, 7.00 through 13.60, but gives no release timeline, console revision breakdown, or version-by-version success rates. It also credits multiple contributors and links the project to a GitHub repository. The available source does not say whether Sony has responded, whether a system update addresses the issues, or whether the listed range has been validated by outside researchers.
“Webkit may need several attempts; reload the page if the browser stalls.”
— Relapse-Exploit project documentation
Reliability and Sony Response
The supplied material does not establish success rates, reproducibility, or performance on particular PS5 models. Although the project lists firmware 7.00 through 13.60, it provides no per-version results in the source text. It is also unclear whether the chain works on every console running those versions, what payloads users can run in practice, or how often the documented hangs and panics occur.
No date is supplied for the project’s publication or latest update, and the source contains no statement from Sony. It does not say whether Sony has investigated or patched the underlying issues, or whether any later firmware versions are affected. The project’s stated support range should not be read as evidence about versions outside that range.
Further Testing Could Clarify Support
The next useful evidence would be independent testing that records results by firmware version and console model, along with the frequency of browser stalls and kernel failures. A dated project update could also clarify which versions the maintainers have tested and whether the listed range has changed.
Readers should watch for any later statements from the project maintainers or Sony about the chain’s status. Until those details appear, the public documentation establishes what the project claims to support and describes its risks, but leaves practical reliability and the platform holder’s response unresolved.
Key Questions
Which PS5 firmware versions does the project list?
The GitHub documentation lists firmware 7.00 through 13.60. It does not provide success rates for each version in the supplied material.
What does the project say the exploit chain does?
It describes a browser stage followed by a kernel stage, with the latter intended to establish kernel read and write access. That is the project’s description; the supplied source does not include independent validation.
What risks does the documentation name?
It warns of browser stalls, console hangs or panics, and possible system instability, data loss, and account bans. It does not quantify the likelihood of those outcomes.
Has Sony responded or patched the issues?
The supplied source includes no Sony statement and does not say whether a patch has been released. The project lists support only through firmware 13.60.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
