Application Security

PS5 Relapse Exploit Unlocks Kernel Access on Firmwares 6.00-7.61

By ScanLabs AI Security Team
September 30, 2026
7 min read
Back to Hub
PS5 Relapse Exploit Unlocks Kernel Access on Firmwares 6.00-7.61 — Application Security illustration | ScanLabs AI
Intelligence Brief

The cybersecurity landscape for gaming consoles has been rocked by the public disclosure of a significant kernel exploit for the Sony PlayStation 5. Dubbed "Relapse," this exploit, detailed on a GitHub repository by ntfargo, targets the console's firmware versions 6.00 through 7.61, leveraging a use-after-free (UAF) vulnerability within the fmod audio library. The discovery and subsequent release of technical specifics provide attackers with reliable kernel read/write primitives, representing a critical bypass of security mechanisms and opening the door to unauthorized code execution, potential homebrew development, and other modifications on affected PS5 systems. While a specific CVE identifier is still pending (currently designated as CVE-2023-XXXX), the implications for console security, user privacy, and the ongoing cat-and-mouse game between console manufacturers and exploit developers are substantial.

The Relapse Exploit: A Technical Deep Dive

The "Relapse" exploit is a sophisticated piece of engineering, demonstrating a deep understanding of the PlayStation 5's internal architecture and the intricate details of its software stack. At its core, Relapse exploits a kernel vulnerability, meaning it targets the very operating system (OS) kernel that manages all hardware and software resources on the console. Gaining kernel-level access is the ultimate goal for exploit developers, as it grants the highest possible privileges, effectively bypassing all system-level security controls.

Specifically, the exploit leverages a use-after-free vulnerability found within the fmod audio library, a third-party component commonly used in game development for sound management. A use-after-free bug occurs when a program attempts to use memory that has already been deallocated. This can lead to unpredictable behavior, including data corruption, program crashes, or, in this critical case, arbitrary code execution. The GitHub repository explicitly states that the Relapse exploit provides "reliable kernel read/write primitives," which are fundamental building blocks for further exploitation. These primitives allow an attacker to read from and write to any location in the kernel's memory, enabling them to alter system behavior, inject malicious code, or extract sensitive data.

The exploit's reliability across a range of firmware versions (6.00 to 7.61) indicates a robust and well-researched vulnerability, not a fleeting edge case. The lack of an assigned CVE-ID at the time of disclosure (CVE-2023-XXXX) highlights the speed at which such exploits can emerge and become public knowledge before official vulnerability tracking catches up.

Who is Affected and Broader Implications for Console Security

The primary individuals affected by the Relapse exploit are owners of PlayStation 5 consoles currently running firmware versions between 6.00 and 7.61. Users on older firmware versions, which might have their own known exploits, and crucially, those who have updated to firmware versions newer than 7.61, are not directly impacted by this specific vulnerability. For those on affected firmware, the existence of a public kernel exploit carries multifaceted implications.

From a user perspective, a kernel exploit on a closed system like the PS5 traditionally paves the way for homebrew development – the ability to run unofficial, user-developed software. This can range from custom applications and emulators to unofficial game backups. While often seen as a positive by enthusiast communities, it also opens the door to piracy and potentially malicious software if users are not careful about their sources. Unlike traditional computing platforms, consoles are designed to be closed ecosystems, and the introduction of unauthorized code disrupts this intended security model.

For Sony, the console manufacturer, this disclosure represents a significant security challenge. Maintaining the integrity of their platform is paramount for protecting intellectual property, ensuring a fair gaming environment, and safeguarding user data. Exploits like Relapse necessitate rapid patching and continuous security vigilance. This ongoing "cat and mouse" game between console manufacturers and the exploit development community underscores the continuous need for robust vulnerability management practices, particularly concerning third-party components like the fmod library. While MITRE ATT&CK primarily focuses on enterprise environments, the techniques employed here align with Privilege Escalation (T1068), as the exploit gains kernel-level access, and Defense Evasion (T1070), by bypassing the console's inherent security measures. The underlying use-after-free is a common software weakness that NIST's Secure Software Development Framework (SSDF) aims to prevent through practices like secure coding and thorough testing.

Recommendations for PS5 Owners and Developers

Given the technical capabilities of the Relapse exploit, specific actions are recommended for both PlayStation 5 owners and the broader software development community, including console manufacturers.

For PlayStation 5 Owners on Affected Firmware (6.00-7.61):

  • Update Your Firmware: The most critical recommendation is to update your PlayStation 5 to the latest available official firmware version as soon as possible. Sony typically releases patches for significant vulnerabilities promptly. While the GitHub description indicates up to 7.61 is affected, newer firmware versions will likely contain a patch for this specific fmod vulnerability. Staying on an older, exploitable firmware exposes your console to potential risks.
  • Exercise Caution with Unofficial Software: If you choose not to update, or if a patch is not immediately available for your specific firmware, be extremely cautious about installing or running any unofficial or unauthorized software on your console. The kernel read/write primitives provided by Relapse could be used to install persistent modifications or even malware.
  • Understand the Risks: Be aware that modifying your console's firmware or installing unofficial software can void your warranty, lead to bans from online services, and potentially brick your device.

For Sony and Software Developers:

  • Prioritize Patching and Deployment: Sony's security teams should prioritize the development and rapid deployment of patches for the fmod vulnerability across all affected firmware versions.
  • Enhanced Third-Party Library Auditing: This incident highlights the critical importance of rigorous security audits for all third-party libraries and components integrated into a product. Even well-established libraries can harbor critical vulnerabilities. The NIST Cybersecurity Framework's Identify function emphasizes asset management and vulnerability scanning as crucial steps to proactively find such weaknesses.
  • Secure Software Development Lifecycle (SSDLC): Implementing a robust SSDLC, encompassing threat modeling, secure coding practices (to prevent common flaws like use-after-free), and comprehensive security testing, is essential to mitigate future exploits. This aligns with the principles laid out in the OWASP Top 10 for web applications, but the underlying secure coding principles apply universally.
  • Proactive Vulnerability Research: Engaging in internal and external vulnerability research programs can help identify and remediate flaws before they are publicly exploited.

The Relapse exploit serves as a stark reminder that even seemingly closed and secure systems like modern gaming consoles are not immune to sophisticated attacks. Continuous vigilance, prompt patching, and a commitment to secure development practices are paramount in navigating this evolving threat landscape. For organizations managing their own digital assets, comprehensive vulnerability scanning is a continuous necessity, and you can scan your site free at ScanLabs AI to identify potential weaknesses.

Frequently Asked Questions

What is the PS5 Relapse exploit?

The PS5 Relapse exploit is a newly disclosed kernel vulnerability for the PlayStation 5 console, leveraging a use-after-free bug in the fmod audio library. It provides attackers with highly privileged kernel read/write capabilities on affected systems.

Which PS5 firmware versions are affected by Relapse?

The Relapse exploit specifically targets PlayStation 5 consoles running firmware versions from 6.00 up to and including 7.61. Users on newer firmware are likely protected, while older firmwares may have other known exploits.

Should I update my PS5 firmware immediately?

Yes, it is strongly recommended that PS5 owners update their console to the latest available official firmware version to ensure they receive any patches for the Relapse exploit and other security vulnerabilities. Staying updated is the best defense against known exploits.


Source: github.com — this analysis is based on reporting from github.com.

Related reading

#cybersecurity#security#vulnerability management#code#attack#nist#aws#exploit

Related articles

ScanLabs AI Security Team

Researched and written by the ScanLabs AI Security Team — the researchers behind ScanLabs AI, an automated website security scanner that checks sites against thousands of known vulnerabilities and the OWASP Top 10. Our team tracks emerging threats daily to help businesses find and fix exposures before attackers do. Articles are AI-assisted and reviewed for technical accuracy.

Run a free security scan