PS5 hacked with first exploit covering nearly all firmware versions

Developer Nathan Fargo has published details of Relapse, a new exploit chain for the PlayStation 5 that works on firmware versions through 13.60.
Fargo describes the project as a proof of concept designed solely for security research and analysis of the console’s protections. Relapse demonstrates how multiple vulnerabilities can be chained together to bypass the security mechanisms built into the PS5 operating system.
Durov’s Code does not support piracy. Modifying PlayStation 5 system software may violate Sony’s terms of service and could result in loss of warranty coverage or restrictions on a PlayStation Network account.
According to Fargo’s technical write-up, Relapse is a two-stage exploit chain. It first compromises the userland environment before targeting the kernel of Prospero, the PS5 operating system based on FreeBSD.
The first stage begins in the console’s WebKit-based browser and exploits a logic flaw involving JavaScriptCore’s structuredClone mechanism. A mismatch between buffers can be used to corrupt Uint8Array metadata, giving the attacker arbitrary read and write access within the browser process. To get around W^X protections, which prevent writable memory from also being executed as code, the exploit uses a return-oriented programming, or ROP, chain assembled from instructions already present on the system.
The next step bypasses kernel address space layout randomization, or KASLR, a security mechanism designed to make the location of critical code in memory unpredictable. Fargo says an incorrect offset calculation in a debugging system call causes the kernel to read beyond the bounds of a data structure, exposing the kernel’s base address.
The core of Relapse relies on a logic flaw in the PS5 kernel’s asynchronous input/output system. According to Fargo, an error introduced with additional waiting modes in the aio_multi_wait system call can cause multiple requests to reference the same internal node. When that node is freed, the resulting use-after-free condition leaves dangling pointers that can be manipulated to modify memory at a chosen address.
The exploit then alters the parameters of a pipe descriptor, or pipe_buffer, to gain unrestricted read and write access to kernel memory. This effectively gives Relapse control over parts of the operating system that are normally isolated from user applications.
In its final stage, Fargo says the exploit escapes the FreeBSD jail used to isolate processes and elevates privileges to root. That makes it possible to load additional software, including etaHEN, a homebrew environment previously used by the PS5 modding community for debugging and extending the console’s capabilities.
Fargo says Relapse has been successfully tested on firmware versions up to 13.60. The exploit chain no longer works on firmware 14.00, which Sony released on September 16.