ZeroHour
Cyber Security Newspublished ()ingested Guru Baran
Part of a story covered by 2 sources: “Nintendo Patches Switch QR-Code Stack Buffer Overflow (CVE-2026-82079) Allowing Nearby Code Execution” — merged summary and timeline →

Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console

mediumVulnerabilityimportance 40CVE-2026-82079
AI summary · glm-5.3

Nintendo patched CVE-2026-82079, a CVSS 7.0 stack buffer overflow in original Switch local wireless allowing nearby code execution via QR-code workflows.

Nintendo patched CVE-2026-82079 (CVSS 4.0 base score 7.0, High), a stack-based buffer overflow in the original Switch's local wireless networking affecting firmware earlier than 23.0.0. An adjacent attacker must scan a QR code displayed by the console, via the Album "Send to Smartphone" feature or Mario Kart Live: Home Circuit, before crafted packets can corrupt memory and enable return-oriented programming for arbitrary code execution. EPSS is approximately 0.16%, Switch 2 is not affected, and Nintendo's advisory was published September 10, 2026.

  • Stack-based buffer overflow in local wireless networking; CVSS 4.0 score 7.0.
  • Exploitation requires wireless proximity plus QR code scan of console workflows.
  • Affects original Switch firmware below 23.0.0; Switch 2 unaffected.
  • EPSS approximately 0.16%; low 30-day exploitation forecast.
  • Patch available in system update 23.0.0.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82079
Stack Buffer Overflow in Nintendo Switch Local Wireless Enables Nearby-Attacker RCE

CVE-2026-82079 is a stack-based buffer overflow (CWE-121) in the Nintendo Switch's local wireless networking functionality, affecting system software versions before 23.0.0. An attacker who is physically within wireless range of a console can send crafted network traffic that overruns a stack buffer during local wireless communication. Using return-oriented programming (ROP), the attacker can achieve arbitrary code execution on the console, consistent with the high-impact (8.4) CVSS score covering confidentiality, integrity, and availability. All Nintendo Switch consoles running system software earlier than 23.0.0 are affected; exploitation requires close physical proximity rather than internet access. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update Nintendo Switch system software to 23.0.0 or later via System Settings > System > System Update; consoles connected to the internet typically download system updates automatically, but verify the installed version manually. Until updated, restrict local wireless (local multiplayer) play to trusted nearby users, since an attacker must be within wireless range and there is no internet-facing exposure. With no public PoC or known in-the-wild exploitation, patching is precautionary rather than urgent.

7.0
  • Nintendo Switch (system software) before 23.0.0
mass≈150 million consoles (Nintendo's cumulative Switch hardware sales)
Full article501 words · extracted from cybersecuritynews.com · click to collapse

Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access information stored on the console.

Tracked as CVE-2026-82079, the flaw affects firmware earlier than 23.0.0 and resides in local wireless networking. The security issue is a stack-based buffer overflow, a memory-corruption weakness that occurs when incoming data exceeds the space reserved on the stack.

An attacker can transmit specially crafted network traffic that corrupts memory and enables return-oriented programming, or ROP. ROP chains together short instruction sequences already in memory, potentially allowing the adversary to redirect program control and run arbitrary operations.

Nintendo Switch Vulnerability

Nintendo says exploitation is limited to specific workflows and requires controlled interaction with a console. The attacker must be within wireless range and directly scan a QR code displayed on the Switch screen or connected television.

The exposed workflows include the Album’s “Send to Smartphone” function and the Send to Smartphone capability used with Mario Kart Live: Home Circuit.

Once the malicious device joins the console’s temporary local wireless environment, crafted packets could target the vulnerable networking code.

A successful attack could compromise confidentiality, integrity, and availability. Nintendo warns that an attacker who meets the required conditions may run unauthorized code or obtain information from the console during a successful attack. However, the narrow proximity and QR-code requirements constrain opportunistic exploitation.

Nintendo assigned CVE-2026-82079 a CVSS 4.0 base score of 7.0, rated High. Its vector describes an adjacent-network attack with low complexity, no privileges required, and passive user interaction, with the greatest assessed impact falling on system integrity.

Third-party databases also list an EPSS probability of approximately 0.16%, indicating a low forecast of exploitation in the wild within 30 days. EPSS is predictive, not proof that exploitation has or has not occurred.

Original Nintendo Switch consoles running versions below 23.0.0 are vulnerable. Nintendo says the issue cannot be exploited to obtain console information from Nintendo Switch 2, distinguishing the newer platform from affected hardware.

The vulnerability was reported by external security researchers, and Nintendo published its initial advisory on September 10, 2026, as detailed in the security advisory published by Nintendo.

Users should install system update 23.0.0 immediately. To check the installed firmware, open System Settings from the HOME Menu, select System, and review the displayed version; System Update starts a manual check.

Consoles connected to the internet will normally download current updates automatically.

If immediate patching is impossible, owners should avoid the affected sharing features, prevent others from viewing or scanning QR codes shown by the console or TV, use only trusted personal smartphones for Album transfers, and avoid unfamiliar Mario Kart Live karts.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/nintendo-switch-code-execution-flaw/