How to jailbreak PS5: 5 proven, painful facts about Relapse

How to jailbreak PS5 just got a public answer: the Relapse exploit chains a WebKit JSC memory leak with a FreeBSD kernel race condition for full kernel r/w on firmware 7.00 to 13.60. 5 proven, painful technical facts every developer needs to know.
Dark blue gradient thumbnail: PS5 jailbroken 1100 stars in 48h Relapse exploit explained for developers

Published: 2026-09-30

Horizontal bar chart showing PS5 firmware versions 7.00 through 14.00+ color-coded red for vulnerable and green for patched
Horizontal bar chart showing PS5 firmware versions 7.00 through 14.00+ color-coded red for vulnerable and green for patched

If you searched how to jailbreak PS5 this week, the PS5 homebrew and security research scene just had its biggest day in years. On September 29, 2026, a developer using the handle ntfargo dropped Relapse-Exploit on GitHub, a two-stage exploit chain that runs unsigned code on any PlayStation 5 running firmware 7.00 through 13.60. Within hours, the repository crossed 1,100 stars and 210 forks. If you have wondered how to jailbreak PS5, the answer is now sitting in a 36-commit public repository, and the technical specifics are worth understanding even if you have no interest in running pirated games.

I spent several hours reading through the repo, the credited researchers’ prior work, and multiple independent analyses to pull together this breakdown. If you are looking up how to jailbreak PS5, this is not a click-by-click guide on how to jailbreak PS5 step by step. It is a developer-focused look at how the exploit chain actually works, what it means for security researchers, what Sony can and cannot do about it, and what the broader implications are for the embedded OS and browser-engine security space.


Table of contents

  1. What Is the Relapse Exploit?
  2. Stage 1: The WebKit JSC Memory Leak
  3. Stage 2: The FreeBSD Kernel Race Condition
  4. Firmware Coverage and Who Is Actually Affected
  5. 5 Proven Facts Security Researchers Need to Know
  6. What This Means for Developers and Platform Engineers
  7. Sony’s Painful Position and What Comes Next
  8. FAQ

What is the Relapse exploit?

The honest answer to how to jailbreak PS5 right now is Relapse, an exploit chain, meaning it is not a single vulnerability but a sequence of two connected flaws that are used together. When people search how to jailbreak PS5 in 2026, this is the specific tool they find. The first flaw lives in WebKit, the browser engine running the PS5’s built-in web browser (and the same engine underlying Safari). The second flaw lives in the FreeBSD-based kernel that Sony calls Orbis OS.

By chaining them, how to jailbreak PS5 becomes real: Relapse goes from a webpage load in the PS5’s system browser to full kernel read/write access, which means it can load any unsigned code, homebrew applications, or custom payloads via an ELF loader that listens on port 9021.

The people behind how to jailbreak PS5 matter: the project lists credits to a group of researchers familiar to anyone who followed the PS4 scene: TheFlow, Flatz, Sleirsgoevy, ufm42, and Sonic_Iso, among others. These are not first-time participants. TheFlow and Flatz each published multiple WebKit and kernel exploits for the PS4 over the past decade. Relapse feels like a synthesis of years of accumulated knowledge applied to the PS5.

For anyone studying how to jailbreak PS5, the repository structure is clean:

  • src/ contains the JavaScript and C source for both exploit stages
  • payloads/ holds prebuilt ELF binaries (FTP server, kernel log viewer)
  • offsets/ stores per-firmware memory offsets required for the kernel stage
  • index.html is the browser entry point served locally via serve.py

So how to jailbreak PS5 in practice means running this chain: the stated use case is security research and homebrew development. Anyone asking how to jailbreak PS5 should note the disclaimer is explicit about that. Whether that holds in practice is a different conversation, but the technical contribution itself is a serious piece of work.


Stage 1: the WebKit JSC memory leak

Walking through how to jailbreak PS5 technically, the browser stage starts in JavaScriptCore (JSC), the JavaScript engine embedded in WebKit. It exploits two weaknesses simultaneously.

In the context of how to jailbreak PS5, the first step is an information leak. JSC allocates and manages JavaScript objects in memory regions it tracks internally. The exploit finds a way to read the base address of one of these regions without requiring any prior privilege. That address becomes the foundation the rest of the chain depends on.

For how to jailbreak PS5, the second weakness is in the structured clone mechanism. In how to jailbreak PS5, structured clone is how web pages pass complex JavaScript objects between contexts (for example, to a Web Worker). The PS5’s version of WebKit has a flaw in how it manages a pool of objects used during this cloning operation. When a structured clone operation reuses an object that has already been freed, the attacker controls what data ends up in that memory slot.

The exploit uses this pool mismatch to corrupt a typed array. When learning how to jailbreak PS5, a typed array in JavaScript is a reference to raw memory viewed through a lens like Uint8Array or Float64Array. If the attacker controls which memory block the typed array points to, they can read from and write to arbitrary memory addresses within the renderer process.

That gives the exploit what security researchers call an ASLR bypass: even though the operating system randomizes where code and data land in memory at each boot, the information leak reveals the actual address, making that randomization useless for this attack surface.

The README warns that this stage is not perfectly reliable. The browser can freeze and require a reload, and the exact success rate depends on timing. This is common with heap-grooming based exploits where the attacker needs the memory allocator to behave in a specific pattern.


Stage 2: the FreeBSD kernel race condition

Once the browser stage has arbitrary read/write within the renderer process, the exploit needs to escape the process sandbox and reach the kernel. This is where the second flaw comes in.

The PS5’s Orbis OS is derived from FreeBSD. The kernel exposes a system call called aio_multi_wait, which lets a process wait for multiple asynchronous I/O operations to complete. The implementation in Orbis OS has a use-after-free (UAF) vulnerability combined with a race condition.

A use-after-free means the kernel frees a chunk of memory but continues to hold a pointer to it. If something else gets allocated in that freed chunk before the dangling pointer is used, the attacker can control the contents of the memory the kernel reads as if it were a trusted kernel object.

The race condition is what makes this exploitable in practice. Two threads race to trigger the UAF at exactly the right moment. If the attacker wins the race (i.e., their allocation lands in the freed slot before the kernel reads it), they gain the ability to read and write arbitrary kernel memory.

From kernel r/w, the exploit installs an ELF loader. An ELF binary is the standard executable format on Linux and FreeBSD systems, so this loader can execute any unsigned code compiled for the PS5’s x86-64 architecture.

The prebuilt payloads in the repo include an FTP server (to transfer files to and from the console over the network) and a kernel log viewer (to inspect kernel output for debugging homebrew software). The kernel log payload in particular is a tool security researchers use to trace system behavior at the lowest level.

Like the browser stage, the kernel stage is not guaranteed to succeed on the first try. The race condition means timing matters, and the console may hang or reboot if the timing is wrong.


Firmware coverage and who is actually affected

The table below summarizes the firmware landscape as of September 30, 2026. Understanding this is central to the question of how to jailbreak PS5 and whether your specific console qualifies:

Firmware Range Relapse Status Approximate Release Period
7.00 to 9.x Vulnerable 2022-2023
10.00 to 11.x Vulnerable 2023-2024
12.00 to 13.60 Vulnerable 2024-mid 2026
14.00.00 and above Patched September 16, 2026
How to jailbreak PS5: Relapse two-stage exploit chain from browser entry to kernel
The Relapse exploit chain: browser entry through JSC info leak to kernel read/write.

Every major PS5 firmware for the past four years falls in the vulnerable range. Sony released firmware 14.00 on September 16, 2026. Thirteen days later, Relapse dropped publicly.

The practical impact: any console that has not been updated in the past two weeks is vulnerable. That includes every retail PS5 or PS5 Pro that sat on store shelves, was shipped to a customer, or was not set to auto-update. Sony has no mechanism to remotely force a firmware update. A console with auto-updates disabled or simply powered off for a month is still on the vulnerable firmware.

There is no official downgrade path for PS5 firmware. A console already on 14.00 cannot roll back. So the window of exposure splits cleanly: updated consoles are safe, everything else is not, and the two populations are now permanently diverging.


5 proven facts security researchers need to know

Here are the five things that matter most to anyone working in embedded OS security, browser engine security, or platform security research. These facts also address the underlying technical question behind “how to jailbreak PS5” at the exploit level, not just the user-facing process.

Fact 1: The WebKit surface is perennially under-hardened. This is not the first time JSC memory leaks and structured clone misuse have been combined to break a locked-down device. iOS jailbreaks have used similar techniques for years. Apple patches them; Sony used an older WebKit build and was slower to backport fixes. The PS5 browser surface is a known attack vector and Relapse proves it still has room to give.

Fact 2: UAF + race condition in async I/O is a known kernel exploit pattern. The aio_multi_wait flaw follows a pattern documented in multiple CVEs for Linux and FreeBSD kernels over the past decade. Async I/O subsystems manage complex object lifetimes across multiple threads, which makes them structurally prone to these bugs. Any embedded OS porting a BSD kernel should be auditing its async I/O implementations specifically.

Fact 3: The exploit is not persistent across reboots. Relapse does not modify any persistent storage. Every reboot clears the jailbreak and requires re-running the full chain. This is actually common in browser-entry jailbreaks because modifying flash storage requires additional steps that are both harder to implement and more likely to brick the device. For security researchers, this is a useful property (the console is always recoverable by rebooting). For persistent homebrew development, it is a daily inconvenience.

Fact 4: The exploit was published the same day Sony argued in court that digital game buyers do not own their games. On August 21, 2026, Sony filed a brief in a federal court case arguing that “reasonable consumers would not be misled into thinking they own the digital games they pay for.” The community response to Relapse was partly shaped by this context. The Decrypt coverage explicitly connected these events. Whether that context affected the release timing is unknown, but it dominated the narrative around the release.

Fact 5: The GitHub MIT license means derivatives are permitted. Relapse was released under the MIT license. This means anyone can fork it, build payloads on top of it, or modify the chain for different purposes. The source code for both exploit stages is public. Closed-source jailbreaks have always eventually leaked, but an MIT-licensed release means the community can iterate openly and Sony cannot easily claim takedowns based on IP rights.


What how to jailbreak PS5 means for developers and platform engineers

If you work on embedded operating systems, browser engines for devices, or platform security, Relapse is worth reading as a case study. The Relapse chain also shows why the practical answer to how to jailbreak PS5 has shifted from “very hard” to “visit a URL” within a single firmware generation.

The browser engine attack surface is not going away. Every modern device ships a browser for developer tools, content stores, or user apps. That browser runs WebKit or Blink, both of which have large, complex JavaScript engines. JSC in particular has been a target repeatedly. If your device ships a browser, your security model must account for the JS engine as a potential entry point to the rest of the system.

The structured clone mechanism specifically deserves attention. Object pool misuse in structured clone has appeared in multiple exploits. It is a complex subsystem with subtle ownership semantics, and it runs in a context that is directly reachable from untrusted web content. If your platform ships WebKit and has not backported the structured clone fixes from the most recent WebKit releases, you should check your exposure.

On the kernel side, the async I/O audit lesson is clear. aio_multi_wait is not a widely-used or heavily-audited interface, but it had the same lifetime management problem that appears in file descriptor tables, socket buffers, and timer objects. When porting a general-purpose OS to a locked-down platform, async I/O implementations deserve a dedicated audit pass focused specifically on UAF scenarios.

Finally, the offset table approach in Relapse is worth noting. The offsets/ directory holds per-firmware memory offsets that the kernel stage needs to know where to aim its writes. This is standard practice for kernel exploits targeting a closed platform with no symbol exports. Maintaining these offsets across firmware versions is significant work, and the fact that Relapse covers 7.00 through 13.60 suggests the offset table was maintained over an extended period, possibly years.


Sony’s painful position on how to jailbreak PS5, and what comes next

Sony is now in a position it has been in before with the PS4 and PS3. The vulnerability is public, the source code is MIT-licensed, and firmware 13.60 and below will remain vulnerable forever because there is no downgrade path from 14.00. Every console owner asking how to jailbreak PS5 right now has a working, public answer for any device that has not been updated since September 16, 2026.

What Sony can do: require firmware 14.00 for all future game releases, online services, and DLC. Games that shipped before September 16 will remain playable on the vulnerable firmware range, but anything going forward can add a firmware gate. This is the pressure valve that will push users to update, gradually shrinking the vulnerable population.

What Sony cannot do: patch the 13.60 and below exploits retroactively, revoke the MIT-licensed source code from GitHub, or force a firmware update onto offline consoles. The vulnerability is in the wild. The relevant CVEs for the WebKit JSC and FreeBSD kernel flaws will be assigned in the coming weeks.

The homebrew scene will iterate on top of Relapse. Expect custom firmware attempts, save game editors, emulators, and debugging tools to follow within weeks. The ELF loader is already there. The question is what the community builds on top of it.

For Sony’s security team, the immediate lesson is that a two-week window between firmware release and public jailbreak is very short. The PS4 scene took years to reach a stable, wide-coverage jailbreak. PS5 got there in under four years of commercial availability. The WebKit attack surface needs continuous patching, not periodic catch-up.


FAQ

Does the Relapse exploit let you play pirated PS5 games? The chain provides kernel read/write and an ELF loader, which in principle can load game files the console would not normally run. Community reports as of September 29, 2026 indicate that some games released before firmware 14.00 have been tested on the jailbroken console. However, learning how to jailbreak PS5 using Relapse does not give you instant access to a piracy pipeline. The exploit is not persistent and requires re-running after every reboot, which complicates any setup involving large game files.

Do I need any special hardware to use Relapse? No additional hardware is required. The exploit enters through the PS5’s built-in system browser. You either point the browser at the GitHub-hosted page or run a local Python server with serve.py after changing the console’s primary DNS setting to 45.56.67.85.

Will this brick my PS5? The exploit does not modify persistent storage. If the kernel stage causes a crash, rebooting restores the console to normal. The risk during the exploit attempt is a hang or reboot, not permanent damage. The README explicitly warns of this possibility and advises rebooting before retrying.

Is using Relapse legal? This depends entirely on your jurisdiction and how you use it. Running homebrew software you wrote on hardware you own is legal in most jurisdictions. If you are researching how to jailbreak PS5 purely for security research or homebrew development, the legal situation is different from using it for piracy. Circumventing copy protection mechanisms may violate the DMCA in the United States or equivalent laws elsewhere. Running pirated commercial games is copyright infringement. The exploit code itself is published under MIT license, but the legal status of using it on your own hardware for non-piracy purposes is a gray area that varies by country.

Who are the researchers credited in the Relapse repo? The main credits include TheFlow (known for multiple PS4 and PS5 WebKit exploits), Flatz (PS4 kernel research), Sleirsgoevy (PS4/PS5 exploit development), ufm42, and Sonic_Iso. This is largely the same research community that built the PS4 jailbreak scene over the past decade, now applying the same techniques to the PS5.

Why does Relapse cover such a wide firmware range? The WebKit vulnerabilities and the aio_multi_wait kernel flaw were not patched in any firmware between 7.00 and 13.60. Sony likely did not know about this specific combination until it was published. The offset table in the repository shows that whoever built Relapse maintained firmware-specific memory offsets for years, suggesting this was a long-running research effort that was held privately before the public release.

What is the developer takeaway from this exploit? If you build software on WebKit or FreeBSD-derived kernels, read the source. The two vulnerabilities Relapse uses are in well-documented subsystems (JSC structured clone, async I/O object lifecycle) that have documented failure modes in the literature. Keeping your browser engine current and auditing async I/O for use-after-free scenarios would have caught both of these.

Related reading: System Design Interview: 7 Proven Fixes for a Painful Round, AI Agent Security Risks: 7 Leaks on My Own Machine, LangGraph Tutorial: 5 Proven Steps to Fix a Fragile Agent.

How to jailbreak PS5: Relapse exploit GitHub star growth 1100 stars in 48h
Relapse GitHub stars: ~1,100 in the first 48 hours after release.

Sources

Shares:
Post a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *