⏱️ Reading time: 10 min

A developer published an exploit chain on GitHub capable of running unsigned code on any PlayStation 5 with firmware between versions 7.00 and 13.60. The project, called Relapse Exploit, turns the system browser into the entry point for a PS5 jailbreak that until now had been fragmented across separate tools by firmware range.

📑 En este artículo
  1. TL;DR
  2. What Is Relapse Exploit
  3. What Happened: Relapse Popularizes a PS5 Jailbreak Without Firmware Fragmentation
  4. Context and History of Jailbreaking on Sony Consoles
  5. Technical Details: Why the Race Condition Is the Key Piece
  6. Impact and Analysis: Security Research, Piracy, and the Gray Area of Jailbreaks
  7. What’s Next for This PS5 Jailbreak and the Rest of the Scene
  8. Frequently Asked Questions
    1. Which PS5 firmware versions are vulnerable to Relapse Exploit?
    2. Does Relapse Exploit allow pirating PS5 games?
    3. Who developed this PS5 exploit chain?
    4. Can Sony block this PS5 exploit chain with an update?
    5. Is it legal to use a jailbreak like Relapse Exploit on a PS5?
  9. References

The repository ntfargo/Relapse-Exploit has accumulated 824 stars and 210 forks as of September 29, 2026, and its own README details the internal mechanism: a memory leak in the WebKit engine and a race condition in the kernel to achieve arbitrary read and write. Sony has not publicly confirmed whether it has already blocked the flaw in firmware versions released after 13.60.

TL;DR

  • Relapse Exploit runs unsigned code on PS5 consoles with firmware 7.00 to 13.60, according to its GitHub repository.
  • It combines a memory leak in WebKit with a UAF race condition in the kernel’s aio_multi_wait.
  • The repository has 824 stars and 210 forks as of September 29, 2026.
  • The authors limit the project to educational purposes and warn of the risk that the console may crash.
  • Sony has not confirmed whether it has already blocked the flaw in firmware versions after 13.60.

What Is Relapse Exploit

Relapse Exploit is an exploit chain published on GitHub by developer ntfargo that runs unsigned code on a PlayStation 5 with firmware between 7.00 and 13.60. It combines a WebKit flaw with a race condition in the kernel to open the console to unauthorized software.

The term “exploit chain” describes a sequence of linked flaws: first a vulnerability in the system browser (the same engine that renders the PS5 store and web apps) to escape the process sandbox, then a second flaw in the kernel to escalate from that limited access to full control over the operating system. It’s the same pattern used by historical iOS and PS4 jailbreaks: a weak link in the software that processes untrusted content, followed by a privilege escalation.

The project is not a one-click installer: it’s the technical documentation and source code for the chain, intended for other developers to build payloads (applications, emulators, debugging tools) on top of it. The repository itself clarifies that its stated goal is security research, not piracy.

What Happened: Relapse Popularizes a PS5 Jailbreak Without Firmware Fragmentation

Until Relapse Exploit appeared, the PS5 modding scene relied on exploits specific to narrow firmware ranges, published and patched separately over the years. Relapse Exploit brings together in a single project firmware coverage from version 7.00 to 13.60, a range that spans several update branches that previously required separate exploits. The repository’s history of 36 commits documents this work as an iterative development effort spanning several months.

The README published by ntfargo details the mechanism without hiding the nature of the project: the browser stage uses information leaks in JavaScriptCore (JSC), the WebKit engine, together with an object-pool mismatch in structured clone to corrupt a typed array. The kernel stage combines the leak of a memory address with a use-after-free race condition in aio_multi_wait to achieve arbitrary read and write over the system.

The team itself warns of instability: the WebKit stage may require several attempts and can freeze the browser, and the kernel stage can hang or reboot the console, so they recommend restarting before retrying.

The chain covers nine major firmware versions, from 7.00 to 13.60. Foto de Albert Stoynov en Unsplash

Context and History of Jailbreaking on Sony Consoles

The Sony console modding scene has nearly two decades of history. On PS3, the cryptographic flaw in signing private key generation exposed by the fail0verflow group in 2010 allowed unsigned code execution; on PS4, researchers like TheFlow and Flatz published kernel and WebKit exploits for years, giving rise to a stable custom firmware (CFW) scene. PS5 inherited much of that security architecture, and with it, several of the same researchers: Relapse Exploit’s credits list includes TheFlow, Flatz, and Sleirsgoevy, names recognizable to anyone who followed the PS4 scene.

Sony has historically responded to each jailbreak with firmware updates that close the specific flaw exploited, without eliminating the full attack surface: the system browser remains a component that processes remote content, and the kernel remains exposed to concurrency bugs like any complex operating system. That pattern (public exploit, patch, new exploit) explains why Relapse Exploit covers such a wide range of versions: it consolidates years of accumulated research work into a single maintainable repository.

Technical Details: Why the Race Condition Is the Key Piece

The mechanism described in the repository relies on two well-known categories of flaws in the software security industry. The first, in the browser stage, is an information leak: a bug in how WebKit manages an object pool during a structured clone operation (the mechanism the browser uses to copy complex objects between contexts) lets the attacker corrupt a typed array, a data structure JavaScript uses to handle binary memory blocks directly. Corrupting that structure gives JavaScript code access to memory addresses that the process sandbox would normally forbid it from touching.

The second, in the kernel stage, is a use-after-free (UAF) race condition: the kernel frees a memory region but a previous reference still points to it, and if the attacker manages to reallocate that region before the operating system safely reuses it, they can control its contents. The specific target, aio_multi_wait, is a function in the asynchronous I/O subsystem of FreeBSD, the base of the PS5 kernel, which derives from FreeBSD just like the PS4’s. Winning that race gives the exploit an arbitrary read/write primitive over kernel memory, the step that separates reading an improper byte from controlling the entire operating system.

This type of race condition is not exclusive to PS5: UAF flaws in asynchronous I/O subsystems have appeared in the Linux kernel, in FreeBSD, and in macOS’s own XNU over the last decade, almost always in code that manages the lifecycle of objects shared between threads. The difficulty with these bugs is that the developer has to win a race against the system scheduler, which is why the README admits that exploitation can hang or panic the console instead of guaranteeing success on the first attempt.

Firmware rangeRelapse Exploit coverageNote
Before 7.00Not coveredRequires prior scene exploits specific to each version
7.00 to 13.60CoveredSeveral firmware branches unified into a single chain
After 13.60UnconfirmedSony has not published whether it has already closed the flaw in more recent versions

flowchart TD
A["PS5 system browser"] --> B["JSC leak and typedarray corruption"]
B --> C["Process sandbox escape"]
C --> D["UAF race in aio_multi_wait"]
D --> E["Kernel read and write"]
E --> F["Unsigned code execution"]

That diagram summarizes the public coverage the project offers: two chained primitives, documented at a general architecture level without publishing exploitation details line by line.

Impact and Analysis: Security Research, Piracy, and the Gray Area of Jailbreaks

Like every PS5 jailbreak, Relapse Exploit enables two uses that coexist in the same code chain: running homebrew (emulators, development tools, community utilities) and running unauthorized copies of commercial games. The repository itself includes a disclaimer that limits its stated use to educational and security research purposes, and clarifies that it does not endorse piracy or unauthorized access to devices belonging to others.

⚠️ Heads up: running this exploit chain on a PS5 with automatic updates enabled or connected to the PlayStation Network can result in a permanent account ban, and the authors themselves warn that the kernel stage can leave the console unable to boot until it’s restarted.

For the security industry, this kind of work has value beyond the console: finding and documenting race conditions in asynchronous I/O subsystems of a FreeBSD-derived kernel also provides information that helps harden other systems built on the same codebase. It’s the same argument that sustained the iOS jailbreak scene against Apple for years: open research finds flaws that the manufacturer would otherwise be the only one to know about.

The other side of the analysis is economic: every stable jailbreak reduces, even if only marginally, software sales revenue that depends on the official store’s distribution monopoly. Sony has not published figures on the impact of previous jailbreaks in its financial results, so there is no way to quantify the effect of Relapse Exploit on PS5 sales with the data available today.

What’s Next for This PS5 Jailbreak and the Rest of the Scene

Sony’s historical pattern with PS3 and PS4 suggests the company will release a firmware update that closes at least the kernel stage of the chain, likely by patching the race condition in aio_multi_wait, without needing to redesign the entire asynchronous I/O subsystem. That would leave only consoles that stay on firmware 13.60 or earlier vulnerable, something that already happened with PS4 firmware branches that were never updated by their owners’ choice.

In the meantime, the developer community is expected to build payloads on top of the base ntfargo published: homebrew loaders, backup tools, and, with less public documentation, utilities for running unofficial game copies. The PS4’s history shows that this payload ecosystem took months to mature after the base exploit was published, so it’s unlikely the chain will be ready for mass use outside the technical community in the short term.

Anyone who wants to review the full technical detail, including the stability notes and the credits list, can open the official Relapse Exploit repository directly on GitHub.

📬 Get new articles by email

We only email about big articles (1-2 a month).

Frequently Asked Questions

Which PS5 firmware versions are vulnerable to Relapse Exploit?

The repository documents coverage from version 7.00 to 13.60. Firmware versions earlier than 7.00 are not covered by this chain and require prior scene exploits; Sony has not confirmed whether versions after 13.60 remain vulnerable.

Does Relapse Exploit allow pirating PS5 games?

Technically yes, because it runs unsigned code, which includes unauthorized copies of commercial software. The repository states that its goal is security research and does not endorse piracy, but the chain itself doesn’t distinguish between legitimate homebrew and illegal copies.

Who developed this PS5 exploit chain?

The GitHub repository is published by user ntfargo, with credits shared with researchers from the Sony console jailbreak scene, including TheFlow, Flatz, and Sleirsgoevy, known for previous work on PS4.

Can Sony block this PS5 exploit chain with an update?

That’s expected based on the company’s history: every public PS3 and PS4 exploit ended up patched in a later firmware update. The race condition in aio_multi_wait is the most likely point for a future patch.

It depends on the jurisdiction and the use. Modifying the software on one’s own device is usually permitted in several countries under interoperability exceptions, but using it to run unauthorized copies of games is a copyright infringement in most jurisdictions, and it also violates Sony’s terms of service.

References

📱 Enjoying this content? Follow @programacion on Telegram for daily tech content in Spanish: quick summaries, fresh content every day.

Featured image: Foto de Amanz en Unsplash

Did it work for you? Got a different error? Say so below: questions get answered and help the next reader.

Leave a comment
Categories: Security

Clara Vásquez

Cybersecurity analyst focused on critical vulnerabilities, zero-days, and emerging threats. Covers high-impact CVEs, malware analysis, ransomware incidents, and security trends with a LATAM lens.

0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *

You can include code inside <code>…</code> or, for several lines, <pre><code>…</code></pre>.

This site uses Akismet to reduce spam. Learn how your comment data is processed.