PS5 Relapse Exploit
- ID
- 30274
- Status
- summarized
- Published
- 29 Sep 2026, 11:44 PM
- Fetched
- 30 Sep 2026, 8:55 PM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://github.com/ntfargo/Relapse-Exploit
- Source URL
- https://hnrss.org/best
Summary
- Score
- 3.5
- Created
- 30 Sep 2026, 8:56 PM
- Tags
- Audience
- developers
What happened
A public GitHub repository, Relapse-Exploit, publishes a working PS5 exploit chain covering firmware versions 7.00 through 13.60, with 1.3k stars and 304 forks. It chains a browser-stage attack using JavaScriptCore info leaks and a structured clone object pool mismatch to corrupt a typedarray, then a kernel stage combining an address leak with an aio_multi_wait use-after-free race to obtain kernel read/write. Delivery is either by setting the console's Primary DNS to 45.56.67.85 or running the included python serve.py / opening the project's GitHub Pages URL, after which an ELF loader listens on port 9021; the README warns the WebKit stage may need several attempts and the kernel exploit may hang or panic the console.
Why it matters
For this audience the practical impact is close to zero: this is a consumer-console jailbreak and nothing here changes what you ship, deploy, or buy. The one transferable detail is the kernel stage's aio_multi_wait use-after-free race combined with an address leak, which is a concrete chaining pattern worth reading if you do low-level or security research. Note also the delivery model - pointing a device's DNS at a third-party server to run unsigned payloads - which is exactly the pattern you should refuse to follow on any machine holding credentials or customer data.
Discussion angle
The repo asks users to point their console's Primary DNS at a fixed third-party IP and then loads arbitrary ELF payloads - is the 1.3k-star distribution model itself the more interesting story than the exploit chain, given how many people will run it without reading the credits or disclaimer?