Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access information stored on the console.
Tracked as CVE-2026-82079, the flaw affects firmware earlier than 23.0.0 and resides in local wireless networking. The security issue is a stack-based buffer overflow, a memory-corruption weakness that occurs when incoming data exceeds the space reserved on the stack.
An attacker can transmit specially crafted network traffic that corrupts memory and enables return-oriented programming, or ROP. ROP chains together short instruction sequences already in memory, potentially allowing the adversary to redirect program control and run arbitrary operations.
Nintendo says exploitation is limited to specific workflows and requires controlled interaction with a console. The attacker must be within wireless range and directly scan a QR code displayed on the Switch screen or connected television.
The exposed workflows include the Album’s “Send to Smartphone” function and the Send to Smartphone capability used with Mario Kart Live: Home Circuit.
Once the malicious device joins the console’s temporary local wireless environment, crafted packets could target the vulnerable networking code.
A successful attack could compromise confidentiality, integrity, and availability. Nintendo warns that an attacker who meets the required conditions may run unauthorized code or obtain information from the console during a successful attack. However, the narrow proximity and QR-code requirements constrain opportunistic exploitation.
Nintendo assigned CVE-2026-82079 a CVSS 4.0 base score of 7.0, rated High. Its vector describes an adjacent-network attack with low complexity, no privileges required, and passive user interaction, with the greatest assessed impact falling on system integrity.
Third-party databases also list an EPSS probability of approximately 0.16%, indicating a low forecast of exploitation in the wild within 30 days. EPSS is predictive, not proof that exploitation has or has not occurred.
Original Nintendo Switch consoles running versions below 23.0.0 are vulnerable. Nintendo says the issue cannot be exploited to obtain console information from Nintendo Switch 2, distinguishing the newer platform from affected hardware.
The vulnerability was reported by external security researchers, and Nintendo published its initial advisory on September 10, 2026, as detailed in the security advisory published by Nintendo.
Users should install system update 23.0.0 immediately. To check the installed firmware, open System Settings from the HOME Menu, select System, and review the displayed version; System Update starts a manual check.
Consoles connected to the internet will normally download current updates automatically.
If immediate patching is impossible, owners should avoid the affected sharing features, prevent others from viewing or scanning QR codes shown by the console or TV, use only trusted personal smartphones for Album transfers, and avoid unfamiliar Mario Kart Live karts.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics…
A critical vulnerability in the AWS Systems Manager Agent could let authenticated attackers bypass remote-host…
A browser extension promoted as a Twitch viewing helper has been found sending live account…
WhatsApp is developing a new privacy control called Restricted Chat that will keep selected conversations…
Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate…
A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially…