New PS5 jailbreak covers firmware up to 13.60.00, reopening piracy debate

A jailbreak called Relapse chains a browser exploit with a kernel bug to unlock PS5 firmware from 7.00 through 13.60.00, before Sony's September patch closed the hole.

AI-drafted from 4 sources. This story was written with AI from the outside reporting listed under Sources, and checked by automated tools before it went up. The originals have the full detail.

A jailbreak for the PlayStation 5 has been published on GitHub, and it works on any console still running firmware 13.60.00 or older, the last version before Sony's 14.00.00 update on 16 September. The tool, called Relapse, chains a browser exploit with a kernel bug to get code execution on the console, according to the project's repository.

The repository lists supported firmware as 7.00 through 13.60, but Kotaku's report is more specific: it says the exploit works on consoles running firmware version 13.60.00, which Sony released in late July, and stopped working once the 14.00.00 update landed on 16 September. Either way, any PS5 that has not been updated past 13.60.00 is exposed, according to Kotaku's writeup.

How the Relapse chain works

The repository describes a two stage attack. The first stage runs in the PS5's web browser and uses information leaks in JavaScriptCore, the browser's JavaScript engine, combined with a mismatch in how the browser pools structured clone objects, to corrupt a typed array in memory. That gives an attacker enough control to move to the second stage, which pairs an address leak with a use after free race condition in a system call called aio_multi_wait to get read and write access to the console's kernel, the part of the operating system that controls everything else.

Setting it up, per the repository's instructions, involves pointing the console's DNS settings at a specific server and either running a local Python script or loading a page hosted on GitHub directly in the PS5 browser. Once the kernel stage succeeds, an ELF loader (a way of running unsigned executable code) listens on a fixed port so homebrew payloads can be pushed to the console. The same instructions warn that the browser stage can take several attempts and that the kernel stage can hang or crash the console outright, in which case the fix is simply to reboot and try again.

The credits list on the repository names more than a dozen contributors, including several people long associated with jailbreaking PlayStation and Switch hardware, among them Flatz, TheFlow and Sleirsgoevy. The project's own disclaimer describes it as intended for “educational and security research purposes only” and says it does not endorse piracy or unauthorised access, language that is standard for releases like this but does nothing to stop anyone using it that way.

Why the firmware window matters

Jailbreaks like this matter for two separate reasons that always arrive bundled together. For homebrew developers and preservationists, kernel level access on a PS5 means the possibility of running emulators, backup tools and unsigned software that Sony has never allowed, the kind of work that has been building steadily as PS5 hacking has matured. For anyone chasing free games, the same access is what makes piracy possible, since a console with kernel read and write can be made to run copies of games it was never sold with a licence to play.

Kotaku's framing leans hard into the second concern, warning that any game released before the September patch could “potentially be compromised by pirates” on unpatched consoles. A commenter on the r/PiratedGames thread discussing the story put it more bluntly, welcoming the exploit as part of a run of bad news for Sony alongside recent progress on PS5 emulation, in the Reddit discussion. On the Hacker News side, where the release first surfaced for a more technical crowd, the discussion thread focused more on the exploit chain itself than on what people might do with it.

What is not yet clear is how many consoles are still sitting on the affected firmware two weeks after Sony's patch, or whether Sony will respond with anything beyond the usual pattern of patching the specific bugs used here in a future update. Consoles already updated to 14.00.00 or later are unaffected, according to Kotaku, so the practical risk narrows over time as more people update, whether they want to or not.

Sources

Image: kotaku.com

More news from Gaming World