AI Weekly Malaysia

Back to items Summaries

PS5 Relapse Exploit

ID
30274
Status
summarized
Published
29 Sep 2026, 11:44 PM
Fetched
30 Sep 2026, 8:55 PM
Provider
Hacker News
Category
dev-community
Original URL
https://github.com/ntfargo/Relapse-Exploit
Source URL
https://hnrss.org/best

Summary

Score
3.5
Created
30 Sep 2026, 8:56 PM
Tags
Audience
developers

What happened

A public GitHub repository, Relapse-Exploit, publishes a working PS5 exploit chain covering firmware versions 7.00 through 13.60, with 1.3k stars and 304 forks. It chains a browser-stage attack using JavaScriptCore info leaks and a structured clone object pool mismatch to corrupt a typedarray, then a kernel stage combining an address leak with an aio_multi_wait use-after-free race to obtain kernel read/write. Delivery is either by setting the console's Primary DNS to 45.56.67.85 or running the included python serve.py / opening the project's GitHub Pages URL, after which an ELF loader listens on port 9021; the README warns the WebKit stage may need several attempts and the kernel exploit may hang or panic the console.

Why it matters

For this audience the practical impact is close to zero: this is a consumer-console jailbreak and nothing here changes what you ship, deploy, or buy. The one transferable detail is the kernel stage's aio_multi_wait use-after-free race combined with an address leak, which is a concrete chaining pattern worth reading if you do low-level or security research. Note also the delivery model - pointing a device's DNS at a third-party server to run unsigned payloads - which is exactly the pattern you should refuse to follow on any machine holding credentials or customer data.

Discussion angle

The repo asks users to point their console's Primary DNS at a fixed third-party IP and then loads arbitrary ELF payloads - is the 1.3k-star distribution model itself the more interesting story than the exploit chain, given how many people will run it without reading the credits or disclaimer?

Top