PS5 Six-Year Defense Falls: How Ordinary Bugs Stitched a Full Exploit Chain

PS5 Six-Year Defense Falls: How Ordinary Bugs Stitched a Full Exploit Chain

SecurityExploitSystems Engineering

Sources:GitHub + HN 讨论

In late September 2026, an exploit chain implementation named Relapse was published on GitHub. The project achieved an unusually broad impact: it bypassed all PS5 firmware defenses spanning versions 7.00 through 13.60. Across six years of continuous system hardening and low-level component patches by Sony, this chain avoided attacking the heavily fortified cryptographic layers altogether. Instead, it chained two seemingly ordinary logic flaws to obtain arbitrary read and write capabilities across the entire system.

Corrupting an Array to Tear Open the Sandbox

The initial breach originated inside a heavily restricted browser environment. The first stage of the Relapse chain combines an information leak in the browser’s JavaScript engine with an object pool mismatch during structured cloning to corrupt a specific internal data structure.

The vulnerability can be visualized as a logic flaw in a luggage locker facility: the management system immediately assigns a newly returned locker to a new guest, yet the previous guest’s key voucher still unlocks the door. At the memory level, this object confusion allows attackers to precisely overwrite the internal metadata of a typedarray. Controlling this typedarray grants an arbitrary read/write primitive within the browser sandbox, serving as a master key to manipulate adjacent memory spaces.

PS5 Console Figure: PS5 console and DualSense controller. Source: Wikimedia Commons

A standalone memory corruption within a sandbox cannot compromise an entire console. However, when such corruption occurs on a springboard at the system boundary, the outermost perimeter is effectively dismantled. Armed with this corrupted memory primitive, the attacker begins deploying the subsequent payload environment from within browser space.

Winning the Microsecond Race to Pierce the Kernel

An out-of-bounds primitive in the browser offers only the initial foothold; achieving full control over the console requires a privilege escalation down to kernel space. The second stage of Relapse targets the kernel’s asynchronous I/O wait mechanism (aio_multi_wait).

Using the kernel address leak obtained from the browser stage, the exploit triggers a use-after-free (UAF) race condition deep in the operating system. Just as the kernel frees a critical memory region and prepares it for reclamation, the exploit races within a microsecond timing window to reallocate and claim the memory before the system reclaims control. Two independent mechanism flaws—neither of which would typically do more than crash a process on its own—are seamlessly chained together.

PS5 Motherboard Teardown Figure: PS5 motherboard, where the attack surface ultimately reached system management and kernel space. Source: Wikimedia Commons

Modern defense architectures rarely fall to direct, brute-force assaults on isolated modules. Instead, state transitions within complex systems remain the hardest to seal completely. The compounding effect of two ordinary flaws successfully bypassed every layer of rigorous cryptographic verification.

A Distributed Open-Source Relay of Over a Dozen Researchers

An exploit chain capable of piercing six years of firmware defenses was not the work of a lone researcher. The project’s acknowledgments section lists more than a dozen developers who contributed critical puzzle pieces across years of research. From early browser vulnerability discoveries and mid-stage kernel address probing to final ELF loader integration, every link in the chain was discovered and stabilized by different researchers at different times.

Defenders no longer face a single adversary targeting a specific vulnerability, but an entire distributed open-source stack. One researcher discovers a structured clone confusion; months later, another connects it to a kernel concurrency edge case. As long as system defenses leave a single logical seam, community research will continue tugging at the thread until a complete pathway to ring 0 is assembled.

Infinite Reboots Against System-Level Defenses

Within Relapse’s documentation, the authors make no attempt to hide the exploit chain’s high failure rate. During the browser phase, the page can easily hang, requiring a simple manual refresh. In the kernel phase, timing misfires may trigger a kernel panic and abruptly cut power, forcing the user to hard-reboot and start over.

Yet attackers can absorb countless failures; hitting the correct memory layout just once is enough to execute the chain, spin up an ELF loader, and await incoming payloads. For the defensive team, a million successful mitigations count for nothing if a single timing race slips through and surrenders full console privileges. Sony’s progressively tightened firmware defense faced an exploit framework founded on probability and unlimited trial and error.

Ecosystem Shifts and the Disillusionment of Veteran Researchers

Community reaction to the Relapse release highlighted another dimension of the security landscape. In online discussions, a veteran scene researcher admitted to stepping away from console research, pointing to structural shifts in the vulnerability hunting ecosystem.

A surge of newcomers now relies heavily on automated tooling and models to rapidly uncover shallow logic bugs, publishing proof-of-concepts immediately upon verification. This rapid disclosure cadence prompts platform vendors to issue quick patches before vulnerabilities can be incorporated into deeper architectural research. Long-term, patient exploration is frequently cut short by fast-paced, superficial disclosures.

This is not the first time the community has weathered such a transition. Earlier, core contributors responsible for porting Linux to the PS5 stepped back amid similar demographic and cultural shifts. Six years of firmware defenses were ultimately penetrated by two mechanical flaws, proving once again that security boundaries are won or lost on complex state management rather than raw cryptographic strength. Stacking ordinary memory discrepancies to shatter entire defensive perimeters is fundamentally reshaping the cadence of modern security offense and defense.

Reference Links:

  • GitHub Relapse-Exploit
  • HN Discussion
  • Wikimedia Commons