PS5 jailbreak tool Relapse goes open source as Sony argues players do not own digital games

PS5 jailbreak tool Relapse goes open source as Sony argues players do not own digital games

N
News Editor
2026-10-01 08:19:18
A newly published PS5 jailbreak exploit chain, Relapse, has appeared on GitHub with support for firmware versions 7.00 through 13.60, drawing 1,469 stars and 353 forks by Oct. 1 after being created on Sept. 17, 2026. Around the same time, Sony Interactive Entertainment told a federal court in California that consumers who buy digital PlayStation games receive a revocable license rather than ownership of the software. According to the repository README, Relapse combines a browser-stage JavaScriptCore information leak and typed array corruption with a kernel-stage exploit involving an address leak and a use-after-free race condition in aio_multi_wait, ultimately granting kernel read and write access. The project says the default payload sits in the payloads directory and the ELF loader listens on port 9021. The README also warns that the WebKit stage may require multiple attempts and that the kernel stage can crash the console or trigger a panic. The legal dispute comes from Heycock v. Sony Corporation of America, where four PlayStation users sued over the PlayStation Store’s “Buy Now” button. Sony later moved to compel arbitration or dismiss the complaint, citing terms that state the software is licensed, not sold. A hearing first set for Oct. 1 was rescheduled on Sept. 29 to Oct. 29.

A PS5 jailbreak exploit chain called Relapse has been released on GitHub, supporting firmware versions 7.00 through 13.60. At nearly the same time, Sony Interactive Entertainment argued in a filing in federal court in California that players do not own digital games they buy, but instead receive a revocable license.

The code is published in the GitHub repository ntfargo/Relapse-Exploit. The repository was created on Sept. 17, 2026, and had reached 1,469 stars and 353 forks by Oct. 1.

What Relapse includes

Relapse is presented as a full exploit chain rather than a simple unlock tool. According to the README, the browser stage uses a JavaScriptCore information leak together with a structured clone object pool mismatch to corrupt a typed array. The kernel stage combines an address leak with a use-after-free race condition in the aio_multi_wait function to gain kernel read and write access.

After a successful run, the default payload is placed in the payloads directory, and the ELF loader listens on port 9021. The README says the WebKit stage may need several attempts and should be reloaded if it stalls. It also says the kernel stage may crash the console or trigger a panic, requiring a reboot before trying again.

The credits list Sonic_Iso for the kernel exploit, Jordy for the WebKit and kernel vulnerabilities, ntfargo and ufm42 for development, and Dr. Yenyen for testing. The project also thanks nine additional researchers.

How it is used and where it stops working

Nathan Fargo, the publisher of the project, identified in the article as the holder of the GitHub account ntfargo and founder of Linear Fox, posted instructions on X. Users are told to change the PS5 primary DNS to 45.56.67.85, open the console’s built-in user guide, enter the exploit page address in the URL bar, and wait a few seconds.

Community reports cited in the article said the process can be completed within seconds. It can be used to load payloads such as etaHEN and then run homebrew software, emulators from multiple platforms, and game backups. The article says it works on both the standard PS5 and the PS5 Pro.

Relapse is not persistent. The full process must be repeated after every reboot. Consoles updated to firmware 14.00 after Sept. 16, 2026 are fully incompatible, which the article describes as Sony having already closed that path before the exploit became public.

The README disclaimer says the project is for education and security research only and does not support piracy or unauthorized access. Users are told they assume the risks of system instability, data loss, and account bans.

Sony’s position in court

The legal filing appeared in Heycock v. Sony Corporation of America. In that motion, Sony Interactive Entertainment wrote: “In the digital age, no reasonable consumer could believe they obtained ‘ownership’ of digital games.”

The case, numbered 3:26-cv-06016 in the U.S. District Court for the Northern District of California, was filed on June 18 by four PlayStation players as a class action. They argued that the “Buy Now” button on the PlayStation Store led consumers to believe they were obtaining lasting usage rights, when in fact they received only a revocable software license.

On Aug. 20, the plaintiffs withdrew their claims against Sony Corporation of America, leaving Sony Interactive Entertainment as the sole remaining defendant. On Aug. 21, Sony moved to compel arbitration or dismiss the complaint, attaching its terms of service and license agreement, which state that the software is licensed, not sold.

Sony also cited an example involving two plaintiffs who bought the same game, Resident Evil Requiem, 11 days apart in February 2026, each paying $69.99. The company used that example to argue that a claim of exclusive ownership does not hold.

A hearing originally scheduled for Oct. 1 was rescheduled on Sept. 29 to Oct. 29.

A dispute over who holds control

The article places the two developments side by side. Sony told the court that players receive a license rather than ownership, while the community response was to use an exploit to bypass the licensing framework and regain direct control over the hardware.

At the same time, the limits of the jailbreak point back to the platform’s control. The exploit does not survive a reboot. It stops working on firmware 14.00. Running it also carries the stated risk of instability, data loss, and PSN account bans.

The next date in the case is Oct. 29, when the court is set to hear Sony’s motion to compel arbitration or dismiss the suit.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.