The Spectrum Dispatch News

technology

PS5 Relapse Exploit Released for Firmware Versions 7.00-13.60

A new PS5 exploit tool has been published on GitHub, targeting multiple firmware versions through technical browser and kernel vulnerabilities.

PS5 Relapse Exploit Released for Firmware Versions 7.00-13.60

A PS5 exploit called Relapse has been released on GitHub, supporting PlayStation 5 consoles running firmware versions 7.00 through 13.60, according to the project repository.

PS5 Relapse Exploit Released for Firmware Versions 7.00-13.60

The exploit works in two stages. The browser stage uses what the documentation describes as “JSC info leaks and a structured clone object pool mismatch to corrupt a typedarray.” The kernel stage then “combines a address leak with an aio_multi_wait uaf race to establish kernel r/w,” according to the technical documentation.

To use the exploit, users are instructed to set their PS5’s Primary DNS to 45.56.67.85, then either run a Python server locally or open a hosted version of the tool in the PS5 browser. The documentation notes that the Webkit browser “may need several attempts” and that users should “reload the page if the browser stalls.” It also warns that “the kernel exploit may hang or panic the console, so reboot before trying again if that happens.”

After a successful run, the documentation states that “the ELF loader listens on port 9021,” with default payloads stored in a payloads directory.

The project credits multiple researchers in its development: ntfargo, ufm42, Sonic_Iso, Jordy, Dr. Yenyen, TheFlow, SlidyBat, Flatz, cow, nhk, bollarz, Sleirsgoevy, EchoStretch, and EarthOnion.

The repository includes a disclaimer stating the project is “intended for educational and security research purposes only” and does not “endorse piracy, unauthorized access, or misuse of commercial devices.” The disclaimer adds that users should only run it “on devices you own or are authorized to test, and comply with applicable laws and regulations.”

The software is provided “as-is, without warranty,” and the documentation warns users to assume risks including “system instability, data loss, and account bans,” with maintainers accepting “no liability for resulting damage.”

Key facts

  • The Relapse exploit targets PS5 firmware versions 7.00 through 13.60
  • The exploit operates through a browser stage that corrupts memory and a kernel stage that establishes read-write access
  • Users must configure their PS5’s DNS settings and run the tool locally or access a hosted version
  • The exploit carries risks including system instability, data loss, and potential account bans
  • The project is described as educational and for authorized security research only

Sources

← All posts