{
  "id": 11552968,
  "title": "Relapse jailbreak exposes PS5 firmware through 13.60",
  "url": "https://urgent.news/2026/10/02/relapse-jailbreak-exposes-ps5-firmware-through-13-60",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T20:42:18.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/relapse-jailbreak-exposes-ps5-firmware-through-13-60/"
  },
  "original_language": "en",
  "account": "A new PlayStation 5 jailbreak called Relapse has exposed kernel-level access on consoles running system software versions 7.00 through 13.60. The open-source project, published by developer ntfargo and others, utilizes a browser-stage JavaScriptCore memory-corruption technique combined with a kernel use-after-free race. This exploit chain establishes kernel read-and-write capability, enabling homebrew software and security research on affected machines. The first stage of Relapse operates through the PS5 browser environment, with the second stage using an address leak and a race involving an aiomultiwait use-after-free flaw. Successful exploitation grants kernel read/write primitives, allowing interaction with protected areas of the console's operating system. Firmware 14.00, released by Sony on September 16, is not vulnerable to Relapse, limiting its relevance to consoles still running earlier system software. The jailbreak is tethered, requiring re-execution after each console restart. While the developers emphasize that the exploit chain is intended for educational and security-research purposes and does not endorse piracy, independent demonstrations have shown it works across the stated firmware range, although reliability varies.",
  "summary": "A newly public PlayStation 5 jailbreak called Relapse has opened kernel-level access on consoles running system software 7.00 through 13.60, including the PS5 Pro, while Sony’s newer 14.00 firmware falls outside the exploit’s stated range. The open-source project, published by developer ntfargo with credits to a wider group of console-security researchers, combines a browser-stage JavaScriptCore…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}