Critical PS5 Kernel Exploit Affects All Firmware Versions
Key Takeaways A new exploit chain, “Relapse,” enables arbitrary code execution on PlayStation 5 and PS5 Pro consoles. The exploit targets firmware versions 7.00 through 13.60, leveraging...
Key Takeaways
- A new exploit chain, “Relapse,” enables arbitrary code execution on PlayStation 5 and PS5 Pro consoles.
- The exploit targets firmware versions 7.00 through 13.60, leveraging a WebKit vulnerability and a kernel bug.
- Successful execution grants kernel read/write access, allowing homebrew applications and unofficial modifications.
- The exploit is “tethered,” meaning it must be re-applied after every console restart.
- Firmware version 14.00 and newer are not affected, as Sony patched the underlying vulnerability in a mid-September 2026 update.
Researchers Unveil Critical PS5 Kernel Exploit Affecting Broad Range of Firmware
Cybersecurity researchers have publicly released a new jailbreak, dubbed “Relapse,” that targets a significant range of PlayStation 5 firmware versions. This two-stage exploit chain grants kernel-level access, potentially enabling the execution of unsigned code on both the standard PS5 and the PS5 Pro models running firmware from 7.00 up to and including 13.60.
Table Of Content
The disclosure marks a notable development for the console modding community, providing a pathway for custom firmware and homebrew applications on systems that have not received Sony’s most recent security updates. It is important to note that this exploit does not compromise all PS5 firmware iterations ever released.
Technical Breakdown of the Relapse Exploit
The Relapse exploit operates in two distinct stages. The initial phase leverages a vulnerability within the console’s integrated browser, specifically exploiting a weakness in its WebKit rendering engine. Following a successful browser-based compromise, the second stage targets a kernel-level flaw, reportedly establishing read and write access to the kernel. This critical level of control is essential for running arbitrary, unsigned code on the console.
Upon successful execution of the exploit chain, an ELF loader is initiated, enabling compatible payloads—including various homebrew tools—to be transferred to and run on the console. Developers have cautioned that both stages of the exploit can be unstable, with the browser component potentially stalling and the kernel stage risking console hangs or crashes.
The exploit’s efficacy is limited by Sony’s update cycle. Firmware version 14.00, which was released in mid-September 2026, effectively mitigates the vulnerabilities utilized by Relapse. Consequently, consoles already operating on firmware 14.00 or those shipped with it are not susceptible to this exploit. Furthermore, official system software downgrades are not supported by Sony, meaning users who have updated to version 14.00 or newer cannot revert to a vulnerable state. Similarly, PS5 builds older than firmware 7.00 are also outside the scope of this particular exploit chain.
Exploit Details and Attribution
According to project specifics published on GitHub, the Relapse jailbreak is a tethered solution. This means that the exploit’s effects are temporary and do not persist across console restarts; the entire chain must be re-executed after every reboot. While this characteristic makes Relapse valuable for research and experimental homebrew development, it renders it impractical for permanent modifications. It is also worth noting that many newer PlayStation 5 games require firmware versions not supported by this exploit.
Credit for the development of Relapse is distributed among several prominent console researchers. Sonic_Iso is recognized for the kernel exploit, while Jordy is credited for both the WebKit exploit and the discovery of the underlying kernel bug. Ntfargo and ufm42 contributed to the overall development, with Dr. Yenyen providing testing support. Additional contributions and assistance are attributed to TheFlow, SlidyBat, Flatz, and other unnamed contributors. Nathan Fargo formally released the project on GitHub as Relapse-Exploit around September 29, 2026.
For end-users, engaging with unofficial code carries inherent risks, including potential system crashes, data loss, and the possibility of a PlayStation Network ban. However, for the cybersecurity research community, this disclosure underscores the continued relevance of chaining accessible browser flaws with unpatched memory vulnerabilities in locked console environments.
What You Should Do
- Update Your Console: Ensure your PlayStation 5 is updated to the latest available firmware version (14.00 or newer). This is the most effective defense against this specific exploit.
- Avoid Unofficial Software: Refrain from installing or running any unofficial or homebrew software on your console, as this can lead to system instability, data corruption, or a ban from PlayStation Network.
- Exercise Caution with Web Browsing: Be wary of visiting untrusted websites through your console’s browser, as exploits often leverage browser vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.