A new open-source exploit gives PS5 consoles kernel-level access

A new open-source exploit gives security researchers kernel-level execution on modern PlayStation 5 consoles.
Developer ntfargo and a team of security contributors published the Relapse Exploit on GitHub, targeting PS5 firmware versions 7.00 through 13.60. The attack chain uses browser memory leaks to corrupt a typedarray, then combines an address leak with an aio_multi_wait race condition to gain full kernel read and write access.
Why it matters: Kernel read and write access gives researchers total control over hardware that Sony keeps locked down tight. Supporting firmware versions all the way up to 13.60 opens up low-level research to a huge share of active consoles.
Know this: Here's the gist on how it works. Researchers point the console's Primary DNS to 45.56.67.85 or load the exploit page locally via Python, which opens an ELF payload loader on port 9021 upon success. It requires patience—the Webkit stage frequently stalls, and kernel panics will crash the console and force a reboot. The creators stress that account bans, crashes, and data loss are real risks.
Expect Sony's security engineers to patch this up quickly.
Sources
- Relapse-Exploit GitHub Repository — https://github.com/ntfargo/Relapse-Exploit
- Hacker News Discussion — https://news.ycombinator.com/item?id=49895304

