PS5 Executable Runs on Apple Silicon iPad: Reverse Engineering Breaches the ARM Frontier

Translating PS5 code on x86 PCs is hard enough, but booting a compiled PS5 binary on an Apple Silicon iPad requires AOT relinking to Windows, runtime x86-to-ARM translation via FEX, and RDNA-to-Metal shading. Here is why this is a watershed moment.

PS5 Executable Runs on Apple Silicon iPad: Reverse Engineering Breaches the ARM Frontier

At first glance, it looks like an elaborate fake or a cloud streaming demo: an unmodified Apple iPad sitting on a desk, booting and running a PlayStation 5 game. No console in the room. No Remote Play. No video stream. Yet independent security researcher and reverse engineer buberlo has pulled off a genuine technical breakthrough: executing a commercial PS5 binary on an Apple Silicon M2 iPad without a console emulator core.

An iPad just ran a PS5 binary.

Not streaming. Not Remote Play. No PS5 in the room. No console emulator.

The PS5 build of Dreaming Sarah, relinked by AnyPS5 and booted on an M2 iPad: walk, jump, talk to NPCs, music, touch controls.

Here's how it works 🧵— buberlo (@buberlo) October 6, 2026

Correction & Architectural Clarification: Following publication, developer buberlo reached out with an important nuance on the execution model: the game code is not natively recompiled to ARM64. Instead, AnyPS5 (created by boykopovar) relinks the binary ahead-of-time into a Windows x86-64 executable, and FEX-Emu inside Madeira (created by Will Faust) handles dynamic runtime translation from x86-64 to ARM64 on the iPad's Apple Silicon M2.

Thanks for the write-up! One nuance: the game code isn't native ARM. AnyPS5 relinks it ahead of time into a Windows program, then FEX translates x86-64 to ARM64 at runtime inside Madeira. Huge credit to boykopovar and Will Faust.— Konrad (@buberlo) October 7, 2026

The demonstrator—running the official PlayStation 5 build of the indie title Dreaming Sarah on an M2 iPad Air 13"—features full gameplay traversal, NPC dialogue, sound playback, and interactive on-screen touch controls. But behind that seemingly simple title screen lies one of the most astonishing multi-tier reverse-engineering feats the emulation community has seen in years.


The Great Architectural Divide: Why ARM Changes Everything

To understand why this is such a monumental development, you have to look at the underlying hardware. When developers run PlayStation 4 or PlayStation 5 software on standard PCs (via projects like Spine, Kyty, or AnyPS5), they benefit from an immense architectural shortcut: both the console and the host PC speak x86-64.

The PS5 is powered by an AMD Zen 2 CPU and an AMD RDNA 2 GPU. When that code is loaded onto an AMD Ryzen or Intel Core gaming rig, the host processor can execute the game's compiled CPU instructions natively. The emulation layer doesn't need to translate assembly instructions on the fly; it simply intercepts Sony's proprietary operating system calls (Prospero / FreeBSD kernel calls, libc, audio engines) and translates graphics API calls (AMD AGC to Vulkan).

The iPad, however, shares virtually nothing with the PlayStation 5:

  • CPU Incompatibility: The iPad is powered by Apple Silicon's 64-bit ARM64 architecture. It cannot natively execute x86-64 machine instructions without an intermediate dynamic binary translator.
  • Memory Consistency: x86 enforces Total Store Order (TSO) memory consistency, whereas ARM utilizes a weakly ordered memory model, presenting severe multithreading synchronization hazards.
  • GPU Architectural Gulf: The PS5 relies on an AMD RDNA 2 Immediate Mode desktop graphics pipeline. Apple's M2 GPU is a mobile Tile-Based Deferred Renderer (TBDR) driven exclusively by Apple's proprietary Metal API.
  • Walled Garden Restrictions: iPadOS strictly confines apps to sandboxed address spaces and normally forbids Just-In-Time (JIT) compilation altogether.

Coercing a current-generation home console binary to run across this architectural chasm on a tablet without a jailbreak required assembling and patching a towering stack of cutting-edge open-source translation layers.


How the Pipeline Works: From PS5 ELF to Apple Silicon Metal

In a detailed technical breakdown published alongside the project's open-source repository, buberlo revealed the four-stage technical pipeline that makes execution possible:

1. Executable Relinking (AnyPS5)

The journey begins with AnyPS5 (created by boykopovar). The tool ingests a decrypted PS5 executable (ELF/eboot) and relinks it ahead of time (AOT) into a standard Windows x86-64 Portable Executable (PE/.exe). It is critical to note that this step does not recompile the CPU instructions into ARM64—the game's compiled x86-64 instructions remain intact. Rather, AnyPS5 swaps out Sony's proprietary system libraries—the kernel, standard C library, audio drivers, controller interfaces, and the AGC GPU driver—with open High-Level Emulation (HLE) reimplementations. The game's original compiled x86 code survives, but the operating system foundation underneath is completely swapped out.

2. Dynamic CPU Translation & Host Integration (Madeira + FEX)

Because the relinked binary is still compiled for x86-64, it cannot directly execute on the iPad's ARM64 processor. This is where Madeira (developed by Will Faust / @willfaustcuber) comes in. Madeira is a sideloaded iOS app designed to run Windows binaries in a single process. Madeira pairs Wine 11 compiled as ARM64EC (ARM64 Emulation Compatible) with FEX-Emu, the state-of-the-art dynamic binary translator. At runtime, FEX intercepts the game's x86-64 instructions and translates them on the fly into native ARM64 instructions that the Apple M2 can execute.

To bypass Apple's notorious prohibition on dynamic code execution without jailbreaking, the setup leverages StikDebug / StikJIT, acquiring JIT debug privileges through a tethered developer session.

3. Overcoming the iPadOS Address Space Wall

One of the project's most treacherous obstacles was memory allocation. On 64-bit Windows, AnyPS5 routinely reserves a massive 448 GiB window of virtual address space. On an iPad, however, the virtual address map is heavily fragmented: 8–12 GiB is locked down with host system mappings, while 64–448 GiB is swallowed by native system reservations.

Attempting to reserve the original window caused immediate memory allocation crashes. Buberlo bypassed the restriction by engineering a lazily committed 4 GiB virtual arena anchored at 464–468 GiB (virtual address base 0x7400000000)—providing the guest binary with the address space it expects without consuming physical tablet RAM.

4. The Shader Transformation Pipeline (RDNA → SPIR-V → Metal)

The final hurdle was graphics rendering. PS5 shaders are compiled ahead of time into AMD RDNA 2 GPU bytecode. AnyPS5's shader recompiler reconstructs this bytecode into standard Vulkan SPIR-V intermediate representation. From there, Khronos Group's MoltenVK ingests the SPIR-V and translates it into Apple Metal draw calls.

However, Apple's M2 GPU has architectural limitations compared to modern desktop Radeon silicon: it lacks vertex subgroup operations and PerVertexKHR inputs. Buberlo patched the compiler to fold provably invariant lane masks away and lowered barycentric coordinate pairs directly into native Metal interpolation, allowing geometry and sprites to rasterize cleanly on the iPad screen.


The Dawn of 9th-Gen Console Reverse Engineering on ARM

Buberlo is quick to emphasize that the project is currently a research prototype rather than a finished consumer emulator. Frame rates have not yet been formally benchmarked, save/load state functionality remains in development, and the tool is strictly aimed at technical proof-of-concept testing with legally dumped games (the repository contains zero game assets, firmware, or proprietary decryption keys).

Yet the significance of this milestone cannot be overstated. We are currently living through a generational transition in consumer computing: from Apple's complete transition to M-series ARM processors, to the rise of Qualcomm's Snapdragon X Elite laptops, to future portable gaming handhelds. For years, conventional wisdom held that high-end console reverse engineering would remain shackled to high-wattage desktop x86 rigs.

The Big Picture: Seeing a PlayStation 5 binary successfully relinked, translated via FEX, mapped, and rendered on an ultra-thin tablet proves that the ARM architectural barrier is not impassable. This research marks the very first documented step toward running 9th-generation console software on mobile ARM hardware—and the implications for long-term digital preservation and portable computing are profound.

To inspect the architecture documents, review the build scripts, or track the project's progress, you can visit the official madeira-anyps5 repository on GitHub.