HomeCyber BalkansSony PS5 Relapse Jailbreak Exploit Utilizes JSC Memory Corruption and Kernel UAF

Sony PS5 Relapse Jailbreak Exploit Utilizes JSC Memory Corruption and Kernel UAF

Published on

spot_img

A recent development in the realm of gaming technology has surfaced with the release of a PlayStation 5 jailbreak chain dubbed Relapse. This ambitious project targets PlayStation 5 and PlayStation 5 Pro consoles that are operating on firmware versions ranging from 7.00 through 13.60. With a growing community of enthusiasts keen on exploring the potential of their gaming devices, such exploits represent both innovation and risk.

The Relapse jailbreak makes use of a sophisticated combination of techniques to gain unauthorized access to the console’s functionality. Specifically, it employs a browser-based JavaScriptCore (JSC) memory corruption method alongside a kernel use-after-free (UAF) race condition. This multifaceted approach illustrates the evolving landscape of cybersecurity and the ongoing cat-and-mouse game between software developers and those seeking to bypass these protections.

The individual behind the release, a developer known as ntfargo, has made the project available on GitHub. In doing so, ntfargo has acknowledged contributions from various collaborators, including Sonic_Iso, who provided insights into the kernel exploit, and Jordy, who assisted in developing the WebKit exploit and addressing related kernel bugs. Other researchers and testers also played a vital role in ensuring the exploit’s capabilities.

Documentation within the repository indicates that the vulnerability supports a wide range of PS5 systems, specifically those that have not yet transitioned to Sony’s latest firmware version, 14.00. Publicly available reports clarify that this newer version does not fall within the exploit’s operational parameters, thereby leaving a significant number of consoles vulnerable to the exploit.

The initial phase of the Relapse exploit begins in the PS5’s browser environment. Here, the first-stage code takes advantage of the JSC, which serves as the JavaScript engine utilized by WebKit. According to the project’s detailed documentation, this phase is centered around information leaks from JSC combined with a structured-clone object-pool mismatch. Such conditions facilitate the corruption of a TypedArray—an object in JavaScript crafted for accessing binary data through a defined memory layout. This corruption can permit attackers to manipulate memory beyond the designated boundaries of the JavaScript sandbox, thereby increasing their control over the system.

However, the exploit does not culminate solely in the browser stage. To secure comprehensive control over the console, Relapse advances to a second stage involving the kernel. This phase combines an address leak with a race condition that affects asynchronous input/output (I/O) handling—specifically, the aio_multi_wait process. The identified flaw, a use-after-free vulnerability, arises when an object is accessed after its memory has been deallocated, allowing for the exploitation of freed memory under closely controlled conditions. This kernel-level exploit is crucial, as it facilitates read and write capabilities on the device, marking a significant escalation in unauthorized access.

Achieving kernel read/write access is pivotal, as it allows for modification or inspection of protected operating system memory, presenting tantalizing possibilities for users interested in customized functionalities or homebrew applications. Once the exploit successfully executes, Relapse initiates an ELF loader that communicates via TCP port 9021, providing a pathway for compatible payloads to be delivered to the console.

The project also includes resources related to payload execution and tools designed for enabling homebrew applications. However, developers caution users that the jailbreak chain remains somewhat unstable. The WebKit phase may necessitate multiple attempts if the browser stalls, while the kernel UAF phase poses a risk of causing the console to hang or encounter a panic, requiring a reboot.

Furthermore, Relapse operates as a tethered jailbreak, meaning that any execution must be repeated after a PS5 restart, as the exploit does not persist through reboots. To mitigate risks, Sony has recommended that PS5 owners keep their systems updated with the latest firmware. While updating can close off known security vulnerabilities, users should remain aware that applying official firmware updates may be irreversible and could hinder compatibility with older software.

Lastly, the Relapse repository issues a warning that engaging with the jailbreak may lead to system instability, data loss, or even sanctions against PlayStation Network accounts. In navigating the world of console modification, users are urged to exercise caution and be aware of the potential ramifications of such exploits. As the landscape of gaming technology continues to evolve, exploits like Relapse serve as a reminder of both the possibilities and perils that accompany innovation.

Source link

Latest articles

Cyber Briefing – 2026.10.02 – CyberMaterial

In a rapidly evolving digital landscape, several key issues related to cybersecurity have emerged,...

Two Zero-Day Vulnerabilities Exploited in Attack on Dutch Institute for Vulnerability

Dutch Cybersecurity Non-Profit Compromised in Agentic AI Attack The Dutch Institute for Vulnerability Disclosure (DIVD),...

Ship Quickly, Verify Independently: Aligning Application Security with AI-Generated Code

AI coding assistants have drastically changed the pace at which software is developed, leading...

More like this

Cyber Briefing – 2026.10.02 – CyberMaterial

In a rapidly evolving digital landscape, several key issues related to cybersecurity have emerged,...

Two Zero-Day Vulnerabilities Exploited in Attack on Dutch Institute for Vulnerability

Dutch Cybersecurity Non-Profit Compromised in Agentic AI Attack The Dutch Institute for Vulnerability Disclosure (DIVD),...