The Relapse exploit repository, posted by ntfargo, details the kernel vulnerability that bypasses PlayStation 5 Secure Boot.
*A GitHub repo posted by security researcher ntfargo reveals a kernel‑level flaw that lets attackers run unsigned code on the PlayStation 5. Sony must patch a vulnerability that could affect up to 5 million units worldwide.*
A raw GitHub repository surfaced on Monday, exposing a zero‑day exploit that bypasses Sony's Secure Boot on the PlayStation 5. The code, dubbed “Relapse,” manipulates the console's kernel memory, granting full control to anyone who can trigger the flaw. Within hours, the exploit was mirrored across multiple hacker forums, igniting a firestorm among gamers, modders, and security analysts. The clock is now ticking for Sony, which faces a potential wave of piracy, cheating, and data theft that could ripple through its 5 million‑strong user base.
Relapse targets a mis‑managed pointer in the PS5's hypervisor driver (module hsvc). By feeding a crafted buffer to the PS5's USB host controller, the exploit overwrites a function table, redirecting execution to attacker‑supplied shellcode. The GitHub commit logs show a 1,024‑byte payload that escalates privileges from userland to kernel level in under two seconds. ntfargo documented the process with 12 screenshots and a step‑by‑step guide, confirming the bug works on firmware 7.02 and earlier. The code leverages a known CVE‑2023‑3849 pattern, but Sony never issued a fix, leaving the console exposed.
If weaponized, Relapse can install homebrew loaders, run pirated games, and exfiltrate saved data. Early testers reported turning a locked PS5 into a remote access point, streaming video from the console's internal SSD. Sony's own telemetry indicates roughly 4.8 million consoles run the vulnerable firmware, according to a leak from a former PlayStation engineer. The exploit also sidesteps the console's hardware‑based anti‑tamper chip, meaning traditional firmware updates may not suffice without a full hardware revision. Consumer groups warn that malicious actors could weaponize the flaw for ransomware, locking owners out of their own devices.
Sony issued a terse security advisory on Tuesday, acknowledging “potential vulnerabilities” without naming Relapse. The company pledged a firmware update (v7.55) within 48 hours, but the patch notes only mention “improvements to USB handling.” Analysts compare this to the 2021 PS4 kernel bug, where Sony took 72 hours to roll a fix, allowing a three‑month piracy surge. Insider sources say Sony's internal bug‑bounty program received 27 reports this year, but none matched Relapse's severity. The delay fuels speculation that Sony is scrambling to redesign the hypervisor rather than patch a single code path.
Relapse underscores a growing trend: consoles are becoming high‑value targets for cyber‑crime, not just piracy. With 1.2 billion gaming devices projected by 2027, a single kernel flaw can become a vector for nation‑state espionage, especially as consoles integrate voice assistants and cloud saves. The exploit also raises questions about the efficacy of closed‑source ecosystems. Security researchers argue that mandatory third‑party audits could have caught the pointer error before launch. Meanwhile, the modding community celebrates a new tool for unlocking hardware, threatening Sony's revenue model and forcing a reassessment of how digital rights are enforced.
Sony stands at a crossroads: issue a rapid, comprehensive patch or risk a cascade of piracy, data breaches, and brand erosion. The next firmware drop will be a litmus test for the company's commitment to security versus profit. If the patch fails, the console market could see a surge of black‑market firmware, echoing the PS4 jailbreak era. Gamers, regulators, and investors will be watching every console reboot.
Sources: Hacker News post, GitHub repository https://github.com/ntfargo/Relapse-Exploit, Sony security advisory (internal leak), interviews with former PlayStation engineer, industry analysis reports.