Critical Nintendo Switch Bug Lets Attackers Run Unauthorized Code
Key Takeaways A critical vulnerability, CVE-2026-82079, has been discovered in the original Nintendo Switch. This flaw allows a nearby attacker to execute unauthorized code and potentially access...
Key Takeaways
- A critical vulnerability, CVE-2026-82079, has been discovered in the original Nintendo Switch.
- This flaw allows a nearby attacker to execute unauthorized code and potentially access sensitive information on the console.
- The vulnerability affects Nintendo Switch firmware versions earlier than 23.0.0.
- A patch is available, and users are strongly advised to update their systems to version 23.0.0 immediately.
High-Severity Flaw Exposes Original Nintendo Switch to Local Code Execution
Nintendo has addressed a significant security vulnerability in the original Nintendo Switch console that could permit an attacker in close proximity to execute arbitrary code and extract data from the device. This high-severity flaw underscores the persistent security challenges even in mature gaming platforms.
Table Of Content
Technical Details of CVE-2026-82079
Designated as CVE-2026-82079, the vulnerability is a stack-based buffer overflow, a common memory corruption issue where an application attempts to write more data to a buffer than it was allocated. This particular weakness resides within the local wireless networking component of the console’s firmware, impacting versions prior to 23.0.0.
Exploiting this flaw involves an attacker transmitting specially crafted network packets. These packets are designed to overflow the buffer, corrupting memory and paving the way for return-oriented programming (ROP). ROP is a sophisticated technique that allows an adversary to chain together existing instruction sequences within the system’s memory, effectively redirecting program flow and enabling the execution of unauthorized operations.
Attack Vector and Conditions
According to a security advisory published by Nintendo, successful exploitation of CVE-2026-82079 is contingent upon specific conditions and user interaction. The attacker must be within the wireless range of the target console and manipulate the user into scanning a malicious QR code displayed either on the Switch screen or a connected television.
The vulnerable workflows include the “Send to Smartphone” feature found within the console’s Album application, as well as the same functionality when used with Mario Kart Live: Home Circuit. Once the attacker’s device joins the temporary local wireless network established by the console for these features, specially crafted packets can target the susceptible networking code.
A successful attack could lead to a compromise of the console’s confidentiality, integrity, and availability. Nintendo warns that an attacker, having met all prerequisites, could run unauthorized code or exfiltrate information. However, the requirement for close physical proximity and user interaction with a QR code significantly limits the potential for widespread, opportunistic exploitation.
Severity and Scope
Nintendo has assigned CVE-2026-82079 a CVSS 4.0 base score of 7.0, classifying it as “High” severity. The attack vector is described as “Adjacent Network” with “Low Complexity,” requiring “No Privileges” but involving “Passive User Interaction.” The greatest impact is assessed to be on system integrity.
Analysis by third-party databases indicates a low estimated probability of exploitation in the wild, with an EPSS (Exploit Prediction Scoring System) score of approximately 0.16% within the next 30 days. It is crucial to remember that EPSS provides a predictive likelihood and does not confirm or deny actual exploitation.
The vulnerability specifically affects original Nintendo Switch consoles running firmware versions below 23.0.0. Nintendo has clarified that the newer Nintendo Switch 2 platform is not susceptible to this particular vulnerability, distinguishing it from the affected hardware.
The flaw was initially reported by external security researchers, and Nintendo released its advisory on September 10, 2026, detailing the vulnerability and the available patch.
What You Should Do
- Update Immediately: All owners of original Nintendo Switch consoles should update their system firmware to version 23.0.0 or later without delay. Navigate to System Settings from the HOME Menu, select System, and then initiate a System Update to check for and install the latest firmware. Consoles connected to the internet typically download updates automatically.
- Avoid Vulnerable Features: If immediate patching is not possible, refrain from using the “Send to Smartphone” function in the Album and with Mario Kart Live: Home Circuit.
- Exercise Caution with QR Codes: Be vigilant about who can view or scan QR codes displayed on your console or connected TV.
- Trusted Devices Only: When using the Album’s transfer features, only connect with trusted personal smartphones.
- Beware of Unfamiliar Karts: For Mario Kart Live: Home Circuit users, avoid connecting to unfamiliar or untrusted karts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.