GBHackers

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF


A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60.

This jailbreak combines a browser-based JavaScriptCore memory corruption technique with a kernel use-after-free race condition.

The project’s source code and documentation outline a two-stage chain that ultimately provides kernel read/write access, allowing affected systems to load unsigned ELF payloads.

Sony PS5 Relapse Jailbreak

The Relapse project was published on GitHub by developer ntfargo, who acknowledges Sonic_Iso for the kernel exploit and Jordy for the WebKit exploit and kernel bug, along with several other researchers and testers.

The repository indicates compatibility with firmware versions 7.00 to 13.60, which includes many PS5 systems that have not yet updated to Sony’s more recent firmware branch, 14.00. Public reports suggest that version 14.00 falls outside the project’s supported range.

Relapse begins in the PS5’s browser environment, where its first-stage code exploits JavaScriptCore (JSC), the JavaScript engine employed by WebKit.

According to the project documentation, this browser stage leverages JSC information leaks combined with a structured-clone object-pool mismatch.

This condition corrupts a TypedArray, a JavaScript object designed to access binary data through a defined memory layout. In exploitation terms, corrupting a TypedArray can let an attacker access or manipulate memory beyond the expected boundaries of the JavaScript sandbox.

However, the browser exploit alone does not provide the system control needed for a complete console jailbreak. Therefore, Relapse proceeds to a kernel-stage exploit that combines an address leak with a race condition involving aio_multi_wait.

This flaw is identified as a use-after-free (UAF) vulnerability, which occurs when code continues to access an object after its memory has been released. By racing the kernel’s asynchronous I/O handling and reusing freed memory under controlled conditions, the exploit aims to achieve kernel-level read and write capabilities.

Kernel read/write access is a crucial escalation point because it lets code modify or inspect protected operating system memory.

After successful execution, Relapse starts an ELF loader that listens on TCP port 9021, enabling compatible payloads to be delivered to the console.

The project includes payload-related files and links to homebrew-enablement tools. However, the repository emphasizes that it is intended solely for educational and authorized security research.

The developers caution that the jailbreak chain is not fully reliable. The WebKit stage may require multiple attempts if the browser stalls, while the kernel UAF phase can cause the console to hang or panic, necessitating a reboot.

Additionally, Relapse is tethered, meaning the jailbreak must be re-executed after the PS5 restarts, as it does not persist across reboots.

To mitigate exposure, Sony recommends that PS5 owners keep their consoles updated with the latest available system software.

Updating can close publicly known exploit paths, but users should be aware that applying official firmware updates may be irreversible and can affect compatibility with older software environments.

The Relapse repository also warns that using it may cause system instability, data loss, and potential sanctions on PlayStation Network accounts.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link