// 1 CRITICAL · 1 ZERO-DAY · 1 CVE · 3 EXPLOIT IN THE LAST 24H→
The Relapse jailbreak chain for PS5 disappeared from GitHub on October 3, 2026. It exploited vulnerabilities in JavaScriptCore and the FreeBSD kernel for firmware versions 7.00 through 13.60.

On September 29, 2026, GitHub user ntfargo published Relapse, an exploit chain that achieves arbitrary kernel read and write on PlayStation 5 running firmware 7.00 through 13.60. Four days later, on October 3, 2026, the repository was archived by its owner and set to read-only. The episode reignites the debate over the sustainability of security research on closed consoles: when proof-of-concept code vanishes faster than it appears, does the disclosure system actually work?

Key Takeaways
  • Relapse combines a JavaScriptCore memory corruption in the browser with a use-after-free in the FreeBSD kernel to gain kernel access on PS5 firmware 7.00-13.60.
  • The exploit is tethered: it does not persist across reboots and requires multiple attempts to work, with a risk of hangs or kernel panics.
  • The repository amassed 824 stars and 210 forks in four days before being archived on October 3, 2026.
  • No official CVEs or vendor confirmation exist regarding the closure of the vulnerability in firmware versions after 13.60.

The Technical Chain: From Browser to FreeBSD Kernel

The first stage of the attack runs through the PS5's integrated browser. According to the repository README, the code exploits "JSC info leaks and a structured clone object pool mismatch to corrupt a typedarray." The TypedArray corruption allows an escape from the JavaScriptCore sandbox and yields memory primitives in the browser process.

The second stage targets the kernel. The README describes the mechanism as combining "a address leak with an aio_multi_wait uaf race to establish kernel r/w." The aio_multi_wait function, part of the FreeBSD async I/O subsystem, contains a use-after-free race condition that enables arbitrary read and write in kernel space. The target is no accident: the PS5 kernel derives from FreeBSD, and that OS's async I/O components have shown historical fragility in other research.

Once the chain completes, the payload activates an ELF loader listening on TCP port 9021. This allows loading unsigned executables on the console. The two-stage structure aligns with the PlayStation jailbreak tradition, where the WebKit browser has served as the privileged entry point for the entire PS4 and PS5 generations.

"Webkit may need several attempts, reload the page if the browser stalls. The kernel exploit may hang or panic the console, so reboot before trying again if that happens" — ntfargo/Relapse-Exploit README

The Flash Archive: Strategic Removal or External Pressure?

The repository contained 36 commits documenting months of iterative development. Credits cite historical PS4 scene figures such as TheFlow, Flatz, and Sleirsgoevy, indicating research rooted in years of shared work. The metric of 824 stars and 210 forks as of September 29, 2026, reported by ElSolitario, testifies to the community's immediate interest.

Then the turn: on October 3, 2026, the owner archived the repository. GitHub displays the notice "This repository was archived by the owner on Oct 3, 2026." Archival renders the code read-only, preventing new issues, pull requests, or modifications. It is not a deletion, but a freeze that pulls the project from active visibility.

The dossier does not specify the reasons for the archival. Two readings are possible: legal pressure from Sony, which has pursued similar actions against console modification tools in the past, or a deliberate choice by the jailbreak scene for controlled distribution, limiting code proliferation beyond the technical community. The absence of public statements from ntfargo leaves both hypotheses unverifiable at this time.

The Problem of Disclosure Without an Advisory

Relapse fits a recurring pattern: technically documented high-complexity vulnerabilities published on GitHub without passing through standard coordinated disclosure channels. No CVEs exist, no vendor advisory exists, no release notes confirm the flaw's closure. Sony generically recommends keeping firmware updated, but has not publicly confirmed whether the vulnerability was fixed in version 14.00 or later.

This absence of standard informational infrastructure has concrete consequences. Users cannot verify whether their console is protected except by installing the latest available firmware, without knowing if that firmware actually closes the Relapse flaws. Security researchers working on FreeBSD-derived systems cannot trace the propagation of the aio_multi_wait vulnerability outside the PlayStation ecosystem. The fragmentation between scene disclosure and institutional disclosure leaves a gap that neither side fills.

The case also raises a platform governance question. GitHub, owned by Microsoft, regularly hosts proof-of-concept code for security vulnerabilities. Owner archival is a legitimate mechanism, but its speed in this case — four days — and the profile of the user, with credits to established researchers, suggest dynamics more complex than a simple individual decision.

Why It Matters

The dossier does not specify corrective measures taken by Sony or the community. It is unconfirmed whether exploits exist in the wild beyond the published proof-of-concept, nor is the geographic distribution of consoles with vulnerable firmware verifiable. Details on the specific WebKit/JSC version affected are missing, and it is unclear whether the flaw was reported to Sony via a bug bounty program prior to publication.

The dossier does document that the exploit is tethered, non-persistent, and requires multiple attempts with a risk of kernel panic. This limits operational impact compared to a persistent threat, but does not eliminate risk for users who run the code: connecting to PSN from a modified console exposes accounts to bans, per Sony's historically documented practices.

Research on Relapse has implications beyond the specific case. The demonstration that browser components on gaming consoles remain a critical attack surface, and that FreeBSD-derived kernels retain vulnerabilities in async I/O primitives, also concerns enterprise systems sharing that codebase. The separation between scene disclosure and institutional disclosure, meanwhile, questions the sustainability of an ecosystem where security research occurs in parallel, without a bridge to vendors.

Relapse has vanished from GitHub, but the code forked in those four days circulates. The question is not whether it will return, but whether the next release will be met with a more transparent response than a silent archive.

FAQ

Does firmware 14.00 protect against Relapse?
Unconfirmed. The dossier documents that firmware 14.00 falls outside the exploit's supported range, but Sony has not publicly verified whether it patched the underlying vulnerabilities.
Does the exploit work on all PS5 consoles?
The documented range is 7.00-13.60. Consoles with earlier or later firmware fall outside the verified facts of the dossier.
Why was the repository archived instead of deleted?
The dossier does not specify the reasons. Archival preserves the code in read-only mode but blocks collaborative evolution. The causes — legal pressure or distribution strategy — remain unverified.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. gbhackers.com
  2. blog.aimactgrow.com
  3. elsolitario.org
  4. cyberpress.org
  5. github.com
  6. playstation.com
  7. any.run