A GitHub repository published by researcher ntfargo documents a complete exploit chain for PlayStation 5 consoles running firmware versions 7.00 through 13.60 — a span covering roughly seven years of Sony's software releases. The chain uses two stages: a browser-level attack through the PS5's built-in WebKit engine, followed by a kernel-level privilege escalation that grants full system read/write access. The browser stage exploits JavaScriptCore info leaks and a structured clone object pool mismatch to corrupt a TypedArray, achieving arbitrary code execution inside the browser sandbox. The kernel stage chains an address leak with a use-after-free race condition in aiomultiwait to escape the sandbox and establish kernel-level memory read/write. Once complete, an ELF loader listens on port 9021 for arbitrary payload delivery. Stability is notably poor. The WebKit exploit requires multiple reload attempts, and the kernel race can hang or panic the console entirely, requiring a hard reboot. This is consistent with race-condition exploits in production — they work, but not reliably, which matters for the distinction between a research tool and a piracy pipeline. The project credits fourteen researchers including well-known PlayStation security figures like TheFlow, Flatz, and Sleirsgoevy, alongside ntfargo and several others. The breadth of contributors suggests this chain assembled incrementally from multiple independently discovered vulnerabilities rather than emerging from a single research effort. Sony's exposure here is structural. The PS5's WebKit browser — used for network setup and basic web access — has been a persistent attack surface since the PS4 era. Every console generation ships a browser engine that inevitably falls behind upstream security patches, and Sony's firmware update cadence creates windows of vulnerability measured in years, not weeks. The 7.00–13.60 range means consoles sold across multiple hardware revisions all share the same exploitable surface. The repository includes a DNS redirect method (Primary DNS set to 45.56.67.85) and a GitHub Pages host, both designed to serve the exploit to consoles without requiring a PC. Default payloads are stored locally after execution. The practical effect is that any PS5 owner on affected firmware can achieve full system access with minimal technical knowledge — the barrier is patience with instability, not skill. The disclaimer frames the project as educational and security research. That framing is legally necessary but practically decorative — the tooling is packaged for end-user consumption, not academic review. The real question is how quickly Sony patches 13.60+ firmware and whether they can close the WebKit surface without removing the browser entirely, a move that would break existing features.