Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60

Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory (TL-2026-2841), also tracked as Relapse, is a medium-severity software vulnerability, first published 2026-10-02. It has no confirmed attribution, affects Sony Interactive Entertainment PlayStation 5 / PS5 Pro system software, maps to 3 MITRE ATT&CK techniques (T1059.007, T1106, T1203), and is covered by 9 detection rules and 13 indicators of compromise.

Key facts for TL-2026-2841

Threat ID
TL-2026-2841
Also known as
Relapse, Relapse-Exploit
Severity
MEDIUM
Status
ACTIVE
Category
VULNERABILITY
First published
2026-10-02
Last reviewed
2026-10-02
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer, gaming
Target regions
Global
Detection rules
9
Indicators of compromise
13

Malware and tooling in Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory

Malware and tooling: Relapse

A public two-stage exploit named Relapse targets PS5 and PS5 Pro firmware 7.00 through 13.60, chaining a JavaScriptCore memory corruption (structured-clone object-pool mismatch) with a kernel use-after-free race in aio_multi_wait to gain kernel read/write and load unsigned ELF payloads. The PoC is MIT-licensed on GitHub, unreliable (stalls, hangs, panics) and tethered. No CVE, CVSS or in-the-wild exploitation is reported.

How Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory works

Relapse is a publicly released, browser-delivered, two-stage exploit chain for Sony PlayStation 5 and PS5 Pro consoles running system software 7.00 through 13.60 (14.00 and later are excluded). It was published on GitHub by ntfargo (repository ntfargo/Relapse-Exploit, MIT licence) and reported by GBHackers on 2026-10-02.

Stage 1 (browser / WebKit): the exploit abuses JavaScriptCore (JSC) information leaks together with a structured-clone object-pool mismatch to corrupt a TypedArray, giving out-of-bounds memory access and arbitrary read/write primitives beyond the normal JavaScript sandbox boundaries. The user must load the exploit page (index.html, served by serve.py) in the console's web browser. Per the README, the WebKit stage may need several attempts and the page should be reloaded if the browser stalls.

Stage 2 (kernel): the exploit uses an address leak plus a use-after-free race condition around the aio_multi_wait asynchronous I/O syscall path in the FreeBSD-based kernel. By racing asynchronous I/O handling and reusing freed memory under controlled conditions, it obtains kernel read/write. On success the chain exposes an ELF loader listening on TCP port 9021, allowing unsigned ELF payloads (default payloads are generated into the payloads/ directory) to be sent to the console.

Operational characteristics: the chain is described by its authors as not fully reliable; failures can produce browser stalls, kernel hangs or panics that require a reboot. It is tethered, so it must be re-run after every reboot. The README states it is for educational and security research only. Credits per the sources: Sonic_Iso (kernel exploit), Jordy (WebKit exploit and kernel bug identification), ntfargo and ufm42 (development), Dr. Yenyen (testing). A separate report (GamerGen/GameGPU) dated around 2026-09-14 describes a PS5 kernel use-after-free affecting firmware up to 13.60 and notes that a full chain also needs a user-space entry point, which Relapse supplies via its JSC stage.

No CVE identifier, CVSS score, vendor advisory or in-the-wild malicious exploitation is reported in the sources; the impact is chiefly on console integrity (unsigned code execution, bypass of platform code-signing) rather than a broad enterprise risk. Sony's general guidance is to keep consoles on the latest system software, noting updates may be irreversible and affect legacy compatibility.

MITRE ATT&CK techniques used in TL-2026-2841

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1106 Native API; T1203 Exploitation for Client Execution

Affected products and versions in Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory

  • Sony Interactive Entertainment — PlayStation 5 / PS5 Pro system software
    Vulnerable versions: 7.00 through 13.60
    Fixed in: 14.00 and later (not supported by the exploit per sources)

Remediation for Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory

Patches

  • Sony system software 14.00 and later (per sources, outside the supported range of the exploit); no CVE or vendor advisory published

Immediate actions

  • Update PS5 and PS5 Pro consoles to system software 14.00 or later, which the sources report is not supported by Relapse
  • Do not browse to untrusted pages or open untrusted exploit hosts from the console web browser

Workarounds

  • Restrict console network egress/LAN access to trusted hosts
  • Block or monitor TCP port 9021 to consoles on managed networks

Longer-term hardening

  • Keep consoles on current official system software; note updates may be irreversible and affect legacy software compatibility
  • Monitor home or lab networks for unexpected hosts serving exploit pages to console IPs and for connections to console TCP port 9021

Weaknesses (CWE) in Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory

CWE-416, CWE-362

Timeline of Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory

  • Earlier WebKit-based PS5 jailbreak (SpecterDev, building on TheFloW) published for firmware 4.03, giving read/write only; context for the browser-to-kernel exploit pattern on PS5.
  • PS5 kernel use-after-free affecting system software up to 13.60 reported by the homebrew/security community (GameGPU); still under analysis and no public exploit chain at that point.
  • Threadlinqs opens tracking TL-2026-2841 as MEDIUM; no CVE, CVSS, vendor advisory or in-the-wild exploitation stated in sources.
  • Repository snapshot at time of research: 38 commits, ~1.6k stars, ~393 forks, MIT licence; README credits Sonic_Iso, Jordy, ntfargo, ufm42, Dr. Yenyen with acknowledgements to TheFlow, SlidyBat and Flatz.
  • Sources confirm the supported range is system software 7.00-13.60 on PS5 and PS5 Pro; 14.00 and later is outside scope. GBHackers warns of instability, data loss and possible PlayStation Network account sanctions for users.
  • GBHackers reports the Relapse jailbreak: kernel read/write, unsigned ELF loading on TCP 9021, tethered and not fully reliable; credits Sonic_Iso, Jordy and ntfargo.
  • Relapse PoC (ntfargo/Relapse-Exploit, MIT licence) public on GitHub, chaining a JSC structured-clone memory corruption with the aio_multi_wait kernel UAF race on firmware 7.00-13.60.

Sources cited for Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory

More in vulnerability

Detection coverage for TL-2026-2841

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2841 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats