New PS5 Relapse Exploit Breaks Into the Kernel Across Years of Firmware Releases
Researchers released Relapse, a tethered PS5 jailbreak chaining a WebKit browser flaw with a kernel bug affecting firmware 7.00–13.60.
The Relapse exploit chain, published on GitHub around September 29, 2026, targets PS5 and PS5 Pro firmware 7.00 through 13.60 using a WebKit browser flaw followed by a kernel exploit granting kernel read/write and unsigned code execution. The tethered jailbreak launches an ELF loader for homebrew payloads and must be rerun after every reboot. Sony's firmware 14.00, released mid-September 2026, closes the flaw, and system software cannot be officially downgraded.
- Two-stage chain: WebKit browser flaw plus kernel exploit for read/write access
- Covers firmware 7.00–13.60 on PS5 and PS5 Pro; tethered, not persistent
- Sony's firmware 14.00 patches the exploited flaws; no rollback possible
- Credits: Sonic_Iso (kernel), Jordy (WebKit/kernel), ntfargo and ufm42 (development)
Full article430 words · extracted from cybersecuritynews.com · click to collapse
Researchers have released a new PlayStation 5 jailbreak, Relapse, that public reports say reaches firmware 7.00 through 13.60 on both the standard PS5 and the PS5 Pro. Coverage has treated the drop as a broad jump for consoles that have not installed Sony’s newer update. It does not crack every firmware ever shipped.
Relapse is a two-stage exploit chain. The first stage runs in the console’s built-in browser and abuses a weakness in WebKit. A kernel stage then follows and is reported to establish kernel read and write access, the control needed to run unsigned code.
After a successful run, the project starts an ELF loader so compatible payloads, including homebrew tools, can be sent to the console. Developers warn that the browser stage can stall, while the kernel stage can hang or crash the console.
The limit is Sony’s update line. Firmware 14.00, released in mid-September 2026, sits outside the stated range, and reporting says that release closes the hole used here. Consoles already on 14.00, or shipped with it, are not supported.
System software cannot be officially downgraded, so owners who installed that update cannot roll back. Builds older than 7.00 also fall outside this chain.
PS5 Relapse Exploit
According to project details published on GitHub, the jailbreak is tethered. It does not survive a restart, so the chain has to be run again after every reboot. That makes Relapse useful for research and homebrew experiments, but unreliable as a permanent change. Some newer games already demand firmware this chain does not support.
Credit is split across familiar console researchers. Sonic_Iso is credited for the kernel exploit, Jordy for the WebKit exploit and the kernel bug, and ntfargo and ufm42 for development, with testing by Dr. Yenyen.
Further help is attributed to TheFlow, SlidyBat, Flatz, and other contributors. Nathan Fargo published the project on GitHub as Relapse-Exploit around September 29, 2026.
For players, the risk is concrete. Unofficial code can cause crashes, data loss, or a PlayStation Network ban. For researchers, the disclosure shows that a reachable browser flaw on a locked console still matters when it is chained with a memory bug the vendor has not yet patched.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.