Games

Two PS5 Security Flaws: The Real Danger Isn't Code, It's a Phone Call

The Relapse jailbreak for older system software made the headlines. But for the average PS5 owner, the bigger threat is a method that takes over accounts without any code, simply by convincing Sony's customer support.

Someone on an old-style phone; sticky notes on the desk, a PS5 and controller behind them (illustration)

The first flaw: The console itself

On September 29, a jailbreak called "Relapse" was released. A jailbreak is the general term for bypassing a manufacturer's software restrictions by taking advantage of security vulnerabilities in a device.

An open padlock and lock picks on a desk next to a PS5 (illustration)

Relapse works on all PS5 and PS5 Pro consoles running system software versions 7.00 through 13.60. According to the project's technical documentation, it uses a two-stage exploit chain: first, it gains entry through a vulnerability in the engine behind the console's web browser, then uses a second flaw in the system kernel to gain read and write access to kernel memory. That allows software not signed by Sony to run on the console.

Sony's version 14.00 update, released on September 16, falls outside Relapse's supported range. The company also released version 14.10 on October 1 and said only that it included "some security fixes"; Sony did not say whether those fixes were related to Relapse. Sony recommends installing system updates as soon as possible.

There's an interesting detail here: every PS5 running system software between 7.00 and 13.60 falls within Relapse's scope. That can also include unopened consoles sitting on store shelves if they shipped with a firmware version in that range. At the same time, this limits the exploit's usefulness: new games and updates often require the latest system software. A user who keeps a console on an older version to preserve the jailbreak may gradually lose access to newer games.

PS5 security has actually been dealing with a deeper issue since the start of the year. In the final days of 2025, reports emerged that encryption keys embedded in the console's processor during manufacturing — and therefore impossible to replace through a software update — had leaked online. The incident was reported by multiple technology and security outlets in early January. Those keys are not a working jailbreak on their own, but they represent a permanent weakening of Sony's position on existing hardware. Relapse comes from a different direction, exploiting software flaws that can be patched through updates.

The second flaw: Your account

The real story is the one that received less attention.

A headset, a phone and purchase receipts on a call center desk (illustration)

On May 18, Colin Moriarty, host of the PlayStation-focused Sacred Symbols podcast and a former IGN editor, lost access to his PlayStation account during a livestream. He hadn't clicked a phishing link or entered his password anywhere. Instead, he received a notification saying that the email address on his account had been changed and two-factor authentication had been disabled.

The method was surprisingly simple. According to reports, the attackers called Sony's customer support team and impersonated the account owner. They needed very little information: the account's PSN username or associated email address, plus a single detail from a past purchase. That detail could be a transaction number, an approximate purchase date, or the amount paid. The support representative was convinced by this information and handed control of the account to the attackers.

In Moriarty's own words, passwords, two-factor authentication and passkeys don't matter in this kind of attack. The attacker isn't bypassing them directly; they're getting support staff to disable them.

What happened next was even more troubling. Moriarty recovered his account within a few hours, but, as he openly acknowledged, he was able to do so because he had contacts inside Sony. When the attackers were kicked out of the account again, they used a kind of "dead man's switch": they sent abusive messages from the account and then reported those messages themselves. Sony's automated system permanently banned the account. That ban was also removed only through Moriarty's contacts.

Not everyone was as lucky. One well-known trophy hunter who had their account taken over using the same method never got it back. French technology journalist Nicolas Lellouche was hacked twice using the same transaction number: after the first incident, Sony added a note to his account intended to prevent support staff from making changes, but that protection still failed to stop the same method from being used again.

And the problem isn't over. On October 3, a well-known member of the PlayStation community with more than 30,000 followers on X said their account had been taken over and its email address changed. As of October 6, there appears to be no public statement or announced fix from Sony specifically addressing this account-recovery weakness. The company's general advice has remained the same for years: don't share account or purchase information with anyone.

Why is the second one more dangerous?

Putting the two issues side by side creates a strange picture. Relapse is a complex exploit chain that requires a high level of technical knowledge. But it can be blocked with a system update and only affects consoles that remain on specific older firmware versions.

A vault with its door wide open and a single admission ticket on the floor (illustration)

The account takeover method requires no technical expertise at all. A phone call, a few pieces of public information and an old purchase record can be enough. No software update can fix that, because the weakness isn't in code — it's in the human identity-verification process. In security, this is called "social engineering": instead of tricking the system, you trick the person operating it.

Even the strongest password and the most secure two-factor authentication are useless if the person holding the key simply hands it to someone else. And this can happen even to an ordinary player who has never modified their PS5 and installs every update on time.

What can you do?

Completely preventing this method depends on Sony changing its own support procedures. But there are still ways to reduce the risk:

Hands tearing up a purchase receipt next to a PS5 controller and a digital security checklist (illustration)

  • Never share purchase information. Transaction numbers, receipts, purchase confirmations and screenshots that show them are exactly the kind of information attackers look for. If you've shared this kind of image on social media in the past, consider removing it.
  • Use an email address for your PSN account that isn't public. An email address is one of the pieces of information an attacker may already have; using one that everyone knows only makes their job easier.
  • Keep two-factor authentication enabled anyway. It isn't enough to stop this specific method by itself, but it remains one of the most important protections against far more common attacks such as password theft.
  • Keep your console updated. Exploits like Relapse can be closed through system updates.
  • Don't buy "cheap" PSN accounts. Stolen accounts can end up being resold online.

The most important thing is not to focus only on which story gets the bigger headline. Jailbreaking is a race followed mostly by security researchers, homebrew enthusiasts and piracy communities. Account security, on the other hand, affects every PS5 owner's digital library, the games they've collected over the years and their saved progress. This week, it took code to open the consoles — but accounts are still being opened by a phone call.

TagsSony

Related posts

All posts