ZeroHour
GBHackerspublished ()ingested Divya
Part of a story covered by 2 sources: “Nintendo Patches Switch QR-Code Stack Buffer Overflow (CVE-2026-82079) Allowing Nearby Code Execution” — merged summary and timeline →

Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code

mediumVulnerabilityimportance 35CVE-2026-82079
AI summary · glm-5.3

Nintendo patched CVE-2026-82079 (CVSS 8.4), a stack buffer overflow in Switch local wireless pairing enabling nearby attackers to execute code.

Nintendo Switch system update 23.0.0 fixes CVE-2026-82079, a stack-based buffer overflow in local wireless networking abused via the QR code sharing process, including Album's 'Send to Smartphone' and Mario Kart Live pairing. A nearby attacker who scans the displayed QR code can send crafted traffic and use return-oriented programming to achieve arbitrary code execution. CVSS scores are 8.4 (v3.1) and 7.0 (v4.0), both rated High. No in-the-wild exploitation is reported and Switch 2 systems are not affected.

  • Stack buffer overflow in Switch local wireless networking, fixed in firmware 23.0.0
  • Exploitation requires wireless proximity plus scanning the displayed QR code
  • CVSS 8.4 (v3.1) and 7.0 (v4.0), both rated High
  • No in-the-wild exploitation, malware payloads or campaigns observed
  • Switch 2 consoles are not vulnerable to this issue

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82079
Stack Buffer Overflow in Nintendo Switch Local Wireless Enables Nearby-Attacker RCE

CVE-2026-82079 is a stack-based buffer overflow (CWE-121) in the Nintendo Switch's local wireless networking functionality, affecting system software versions before 23.0.0. An attacker who is physically within wireless range of a console can send crafted network traffic that overruns a stack buffer during local wireless communication. Using return-oriented programming (ROP), the attacker can achieve arbitrary code execution on the console, consistent with the high-impact (8.4) CVSS score covering confidentiality, integrity, and availability. All Nintendo Switch consoles running system software earlier than 23.0.0 are affected; exploitation requires close physical proximity rather than internet access. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update Nintendo Switch system software to 23.0.0 or later via System Settings > System > System Update; consoles connected to the internet typically download system updates automatically, but verify the installed version manually. Until updated, restrict local wireless (local multiplayer) play to trusted nearby users, since an attacker must be within wireless range and there is no internet-facing exposure. With no public PoC or known in-the-wild exploitation, patching is precautionary rather than urgent.

7.0
  • Nintendo Switch (system software) before 23.0.0
mass≈150 million consoles (Nintendo's cumulative Switch hardware sales)
Full article470 words · extracted from gbhackers.com · click to collapse

Nintendo released system version 23.0.0 to address CVE-2026-82079, a vulnerability in the Nintendo Switch’s local wireless networking that could turn the QR code sharing process into an attack vector.

This issue affects consoles running firmware older than version 23.0.0, allowing a nearby attacker to execute unauthorized code or access data stored on the device.

Nintendo Switch QR Code Vulnerability

A malicious QR code does not cause this vulnerability. Instead, the on-screen code is part of a local wireless pairing process that facilitates the attack.

According to Nintendo, an attacker must directly scan the QR code displayed on a Nintendo Switch or a connected television to exploit the issue. The exposed functionalities include the Album application’s “Send to Smartphone” option and pairing karts in Mario Kart Live: Home Circuit.

Technical CVE records indicate that the root cause is a stack-based buffer overflow in the Switch’s local wireless networking. A buffer overflow occurs when input exceeds the memory allocated for it, potentially overwriting control data.

An attacker within the wireless range could send specially crafted network traffic and use return-oriented programming (ROP) to achieve arbitrary code execution. The CVSS v3.1 base score is 8.4, while the CVSS v4 base score is 7.0; both classify it as High.

The proximity and interaction requirements for exploitation help limit exposure. An attacker needs to be close enough for the local wireless exchange and able to view and scan the transient QR code at the right moment.

Scenarios such as public places, shared homes, events, and screen-sharing over an external display present a higher risk than broader internet attacks. Nintendo’s warning states that the attack cannot be executed if a third party cannot scan the displayed QR code directly.

Successful exploitation could compromise the console’s security boundaries, allowing unauthorized code to run and exposing locally stored data. Currently available technical descriptions do not indicate in-the-wild exploitation, malware payloads, or organized campaigns.

Consumers should treat this as a priority vulnerability for patching, while avoiding unsupported claims that every QR scan poses a risk to the Switch.

Nintendo Switch owners are advised to install version 23.0.0 by navigating to System Settings, then System, and selecting System Update. Until the patch is applied, users should avoid QR-based sharing and pairing with untrusted individuals, keep QR codes on the console or TV out of sight, and use only trusted phones and accessories.

Nintendo’s announcement also notes that Switch 2 systems are not vulnerable to information disclosure through this scenario. However, users should still apply the latest firmware updates as part of standard security practices.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/nintendo-switch-qr-code-vulnerability/