PS5 Y2JB Autoloader v1.0.0 Loads Payloads Without a Third-Party DNS

itsPLK's v1.0.0 autoloader runs a WebKit exploit and sends your ELF payloads on PS5 firmware, served straight from the console.

grumpy_bootrom2026-10-10· r/ps5homebrew

A new PS5 homebrew tool, the Y2JB Autoloader v1.0.0 from itsPLK, runs a WebKit exploit and then sends your ELF payloads automatically. The Reddit post says it covers firmware 4.00 to 13.60, but the project README says 7.00-13.60. The release is called Y2JB, while the repo is ps5-webkit-autoloader. The sources don’t settle which firmware range or name is right, so check the release notes first.

Why should you care? Because of how most WebKit setups work. The exploit usually gets triggered by pointing your PS5’s DNS at a server someone else runs. You’re trusting that person, and if the server goes down or changes, your setup breaks. This autoloader works differently. After a one-time install from your PC, everything is served from the PS5 itself. No outside DNS, nothing to vanish behind your back.

The install depends on whether you’re already jailbroken. If you are:

  1. Send the installer ELF (webkit-autoloader-installer_vX.Y.Z.elf) with elfldr, or launch it from Payload Manager.
  2. Let it cache the autoloader page. Pick Poops or Relapse if it asks.
  3. Reboot once, then open WebKit Autoloader from the homescreen.

If you’re not jailbroken yet, you run webkit-autoloader-host.py (or the .exe) on a PC on your network, point the PS5’s DNS at that PC’s IP, and run the installer from the User’s Guide in Settings. Then reboot once.

For payloads, you have two options. With no config found, the loader opens Payload Manager, a web UI you use from your browser. Or you build a ps5_autoloader folder on a USB drive root or in /data/ps5_autoloader, add your ELFs and an autoload.txt, and list the filenames one per line. Names are case-sensitive. Lines like !1000 add a 1000 ms wait.

One catch: the bundled elfldr only accepts connections from the console itself. If you want a regular ELF loader that takes payloads from any device, load it through Payload Manager. Be careful with etaHEN in the same chain. The README says to add a sleep after a custom loader, so it has time to start listening.

My take: the offline part is the real news. Anyone who has run a DNS-hosted exploit knows how fragile that setup gets. This is a quality-of-life upgrade, not a new exploit. The disclaimer says research and development only, at your own risk. Credits go to jordyidk and contributors (slopkit, Poops), soniciso1 and ntfargo (Relapse), and john-tornblom (ps5-payload-sdk and elfldr).