Nintendo: Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data

Nintendo: Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data

Nintendo Switch Vulnerability Exposes Original Consoles to Remote Exploits

Nintendo has disclosed a critical vulnerability (CVE-2026-82079) affecting the original Nintendo Switch, prompting an urgent firmware update for users who play in public spaces. The flaw, a stack-based buffer overflow, allows attackers within wireless range to execute unauthorized code or extract data from the console by exploiting the Send to Smartphone feature or Super Mario Kart: Home Circuit’s QR-based multiplayer setup.

The vulnerability stems from the QR code mechanism used to transfer screenshots or establish local wireless connections. If an attacker scans the code before the intended user, they can gain access to the console, potentially compromising stored account information. The issue is exclusive to the original Switch newer models, including the upcoming Nintendo Switch 2, remain unaffected.

Nintendo released firmware version 23.0.0 on September 9, patching the flaw, and publicly disclosed the vulnerability the following day. Users can update via System Settings > System > System Update. For those unable to update immediately, Nintendo recommends avoiding public use of the vulnerable features and refraining from scanning QR codes with untrusted devices.

The exploit requires physical proximity, meaning users who game exclusively at home face minimal risk. However, those playing in shared spaces such as cafes or transit are advised to apply the update promptly, given the rapid disclosure timeline. Nintendo has not provided further details beyond its advisory.

Source: https://thecyberexpress.com/nintendo-switch-vulnerability/

Nintendo cybersecurity rating report: https://www.rankiteo.com/company/nintendo

"id": "NIN1789460618",
"linkid": "nintendo",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Original Nintendo Switch users '
                                              'in public spaces',
                        'industry': 'Gaming',
                        'location': 'Japan',
                        'name': 'Nintendo',
                        'type': 'Company'}],
 'attack_vector': 'Wireless Proximity Exploit (QR Code-Based)',
 'customer_advisories': 'Users advised to update firmware via System Settings '
                        '> System > System Update and avoid scanning QR codes '
                        'with untrusted devices.',
 'data_breach': {'data_exfiltration': 'Potential',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Personally Identifiable Information '
                                        '(PII)',
                 'type_of_data_compromised': 'Account information'},
 'date_publicly_disclosed': '2026-09-10',
 'description': 'Nintendo has disclosed a critical vulnerability '
                '(CVE-2026-82079) affecting the original Nintendo Switch, '
                'prompting an urgent firmware update for users who play in '
                'public spaces. The flaw, a stack-based buffer overflow, '
                'allows attackers within wireless range to execute '
                'unauthorized code or extract data from the console by '
                'exploiting the **Send to Smartphone** feature or **Super '
                'Mario Kart: Home Circuit**’s QR-based multiplayer setup. The '
                'vulnerability stems from the QR code mechanism used to '
                'transfer screenshots or establish local wireless connections. '
                'If an attacker scans the code before the intended user, they '
                'can gain access to the console, potentially compromising '
                'stored account information.',
 'impact': {'data_compromised': 'Stored account information',
            'identity_theft_risk': 'Potential',
            'systems_affected': 'Original Nintendo Switch consoles'},
 'post_incident_analysis': {'corrective_actions': 'Firmware patch (version '
                                                  '23.0.0) to address the '
                                                  'vulnerability',
                            'root_causes': 'Stack-based buffer overflow in QR '
                                           'code mechanism for local wireless '
                                           'connections'},
 'recommendations': 'Apply firmware update (version 23.0.0) immediately and '
                    'avoid using vulnerable features in public spaces.',
 'references': [{'source': 'Nintendo Advisory'}],
 'response': {'communication_strategy': 'Public advisory via firmware update '
                                        'notification and system settings',
              'containment_measures': 'Firmware update (version 23.0.0) '
                                      'released on September 9, 2026',
              'remediation_measures': 'Avoid public use of vulnerable features '
                                      'and refrain from scanning QR codes with '
                                      'untrusted devices'},
 'title': 'Nintendo Switch Vulnerability Exposes Original Consoles to Remote '
          'Exploits',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'CVE-2026-82079 (Stack-Based Buffer Overflow)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.