Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF
Researchers released Relapse, a tethered PS5 jailbreak for firmware 7.00–13.60 using WebKit JSC corruption and a kernel use-after-free.
Developer ntfargo published Relapse, a tethered PlayStation 5 jailbreak for PS5 and PS5 Pro firmware 7.00 through 13.60; firmware 14.00 is outside the supported range. The browser stage exploits JavaScriptCore with information leaks and a structured-clone object-pool mismatch that corrupts a TypedArray. A second stage combines an address leak with a race in aio_multi_wait to trigger a kernel use-after-free and obtain kernel read/write, then starts an ELF loader on TCP port 9021. The authors say the chain is unreliable, must be re-run after reboot, and is meant for research, while Sony advises installing the latest system software.