On September 29, 2026, Relapse—a project claiming an exploit chain for PlayStation 5 firmware versions 7.00 to 13.60—became publicly available. The headline “the PS5 has been hacked” overstates what the facts support: this is neither a universal nor a persistent jailbreak, but a tool with a claimed support range whose reliability on every version has yet to be established. The range and mechanism are described in the project repository, but its README is the developers’ original claim, not an independent audit.
What was released
Relapse consists of several stages: a browser exploit, followed by a kernel vulnerability and a loader for additional code. The developers list support for firmware versions 7.00–13.60; the later 14.00 version is not included in the claimed range. The public release on September 29 and the need to run the exploit again after reboot are also reported by Tbreak.
It is important to distinguish the release of a tool from confirmed functionality on every console version. The available materials do not include a systematic independent test of every firmware version on the list. It is therefore more accurate to say that the range is claimed by the developers and reflected in reports about the release, rather than treating every version as independently verified.
How the chain works—without launch instructions
According to the README, the first stage exploits the JavaScriptCore engine in the PS5 browser. The developers point to information leaks and an inconsistency in structured clone object handling that makes it possible to corrupt a typed array—a data structure that stores elements of the same type in memory.
But a browser-context bug alone does not provide kernel control. To escalate privileges, Relapse reportedly uses a separate aio_multi_wait bug: a memory-address leak and a use-after-free race condition. If the chain succeeds, it is intended to provide read and write access to kernel memory. An ELF loader can then accept additional code.
This description lays out the basic logic: entry through the browser, escalation to higher privileges through the kernel, then execution of additional programs. But claimed kernel access does not prove that every protection layer is bypassed, and the presence of a loader does not mean that every payload is ready or compatible with every firmware version.
What this means for console owners
Relapse is not installed as a permanent modification. It has to be run again after the console reboots—a point noted by both the developers and Tbreak’s report. So successfully launching the exploit does not mean unsigned code will remain available after the PS5 is turned off and back on.
The developers also warn about freezes, kernel crashes, data loss, and the risk of an account ban. These are warnings from the project, not an assessment of how likely those outcomes are: no published data is available to calculate their probability.
Do not automatically equate launching the exploit with being able to run any game or new release. That requires compatible additional software and separate, verifiable demonstrations. The available materials do not support claims that Relapse guarantees the launch of any specific game.
Early reports: crashes, but no statistics
In a Reddit discussion, one user described freezes during the aio check and said that, after several attempts, the exploit eventually reached the loader. This is a single user report, not a controlled test; it does not show how often Relapse succeeds or freezes. The README also warns that the browser stage may require repeated attempts and that the kernel stage can cause a freeze or system crash.
What is known—and what isn’t yet
The public release of Relapse is a notable event for the PS5 scene: the project claims a chain from browser context to kernel memory access across a broad range of firmware versions. But those claims need to be read with caveats. The mechanism and range are described by the developers; the materials reviewed do not include independent testing of every version. Early community reports describe isolated crashes, not overall statistics. And launching the exploit does not, by itself, confirm a persistent jailbreak, compatibility with new games, or an inevitable ban.