Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data
A newly disclosed Nintendo S 2026-9-15 07:11:37 Author: thecyberexpress.com(查看原文) 阅读量:3 收藏

Nintendo Switch Vulnerability

A newly disclosed Nintendo Switch vulnerability is pushing owners of the original console toward an urgent firmware update, particularly those who tend to play in public spaces. Nintendo confirmed the vulnerability in Nintendo Switch systems in a PDF advisory released Sept. 10, just a day after quietly shipping firmware version 23.0.0 to address the problem. 

Importantly, this vulnerability in Nintendo Switch hardware is limited to the original console. The Nintendo Switch 2 is not affected in any way. 

How the Nintendo Switch Vulnerability Works? 

The flaw centers on the Send to Smartphone feature, a tool original Switch owners use to move screenshots and game captures onto a phone by scanning a QR code generated on the console. That same QR-code mechanism is also used by Super Mario Kart: Home Circuit when played on its physical cartridge, since the game relies on a QR code to establish a wireless connection between nearby players. 

The danger arises when someone other than the intended user scans that QR code first. Doing so lets a stranger’s device link up with the Switch console, opening the door to running unauthorized code on the machine or pulling data straight off it. Because account information lives on the console itself, that’s a real risk for anyone exposed to this Nintendo Switch vulnerability while gaming around others. 

Nintendo has not offered additional detail beyond its advisory. A company representative did not immediately respond when asked for further comment on the matter. 

The vulnerability in Nintendo Switch firmware has been formally logged as CVE-2026-82079. It’s described as a stack-based buffer overflow, a type of flaw that can allow an attacker within wireless range to execute code on the device. The issue only exists on original Switch consoles running firmware older than version 23.0.0; anything on that version or newer is already protected. 

Fixing the Nintendo Switch Vulnerability 

Nintendo’s remedy is straightforward: install firmware 23.0.0, which the company released Sept. 9, one day before publicly disclosing the flaw. To do so, owners should navigate to System Settings, then System, then System Update, and follow any prompts that appear on screen to complete the installation. 

For anyone who can’t update right away, Nintendo has outlined a few stopgap measures. The company suggests only using the Send to Smartphone feature at home, where a stranger isn’t in scanning range, and avoiding public sessions of Super Mario Kart: Home Circuit until the update is applied. More broadly, Nintendo advises against ever scanning a QR code using a device that isn’t your own. 

Players who exclusively game at home are already shielded from this particular vulnerability in Nintendo Switch systems and don’t need to take any further action, since the exploit depends on a nearby attacker being in physical wireless range to intercept the QR code. 

Given how quickly Nintendo moved from patch release to public disclosure — releasing the fix Sept. 9 and detailing the vulnerability the very next day — owners are being urged to update sooner rather than later, especially if they regularly play in cafes, transit, or other shared spaces where an unfamiliar device could realistically pick up a stray QR code. 


文章来源: https://thecyberexpress.com/nintendo-switch-vulnerability/
如有侵权请联系:admin#unsafe.sh