Nintendo Patches Switch QR-Code Stack Buffer Overflow (CVE-2026-82079) Allowing Nearby Code Execution
Nintendo fixed CVE-2026-82079, a stack buffer overflow in original Switch local wireless networking, in system update 23.0.0; a nearby attacker who scans the console's displayed QR code could achieve arbitrary code execution.
Nintendo Switch system update 23.0.0 patches CVE-2026-82079, a stack-based buffer overflow in the original Switch's local wireless networking. Exploitation requires an attacker in wireless proximity who scans a QR code displayed by the console — via the Album 'Send to Smartphone' feature or Mario Kart Live: Home Circuit pairing — after which crafted packets can corrupt memory and enable return-oriented programming for arbitrary code execution. Both sources agree the CVSS 4.0 base score is 7.0 (High); GBHackers additionally reports a CVSS 3.1 score of 8.4 (also High), while Cyber Security News does not cite a v3.1 score. Only firmware versions earlier than 23.0.0 are affected, and Switch 2 consoles are not vulnerable. Cyber Security News reports an EPSS of approximately 0.16% (low 30-day exploitation forecast) and dates Nintendo's advisory to September 10, 2026; GBHackers reports no in-the-wild exploitation, malware payloads, or campaigns observed.
- CVE-2026-82079 is a stack-based buffer overflow in the original Nintendo Switch's local wireless networking.
- Fixed in Nintendo Switch system update / firmware 23.0.0; affects firmware earlier than 23.0.0.
- Exploitation requires wireless proximity plus the attacker scanning a QR code displayed by the console via Album's 'Send to Smartphone' feature or Mario Kart Live: Home Circuit, followed by crafted packets and return-oriented programming…
- CVSS 4.0 base score 7.0 (High); GBHackers also reports CVSS 3.1 score 8.4 (High) — sources agree on the v4.0 figure.
- EPSS approximately 0.16%, indicating a low 30-day exploitation forecast (per Cyber Security News).
- Nintendo Switch 2 consoles are not affected.
- No in-the-wild exploitation, malware payloads, or campaigns reported.
- Nintendo's advisory was published September 10, 2026 (per Cyber Security News).
Coverage timelineoldest first · each row is one article
- · 1d agoNintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console
Cyber Security News· 40
Nintendo patched CVE-2026-82079, a CVSS 7.0 stack buffer overflow in original Switch local wireless allowing nearby code execution via QR-code workflows.
- · 1d agoNintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code
GBHackers· 35
Nintendo patched CVE-2026-82079 (CVSS 8.4), a stack buffer overflow in Switch local wireless pairing enabling nearby attackers to execute code.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82079 | Stack Buffer Overflow in Nintendo Switch Local Wireless Enables Nearby-Attacker RCE CVE-2026-82079 is a stack-based buffer overflow (CWE-121) in the Nintendo Switch's local wireless networking functionality, affecting system software versions before 23.0.0. An attacker who is physically within wireless range of a console can send crafted network traffic that overruns a stack buffer during local wireless communication. Using return-oriented programming (ROP), the attacker can achieve arbitrary code execution on the console, consistent with the high-impact (8.4) CVSS score covering confidentiality, integrity, and availability. All Nintendo Switch consoles running system software earlier than 23.0.0 are affected; exploitation requires close physical proximity rather than internet access. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update Nintendo Switch system software to 23.0.0 or later via System Settings > System > System Update; consoles connected to the internet typically download system updates automatically, but verify the installed version manually. Until updated, restrict local wireless (local multiplayer) play to trusted nearby users, since an attacker must be within wireless range and there is no internet-facing exposure. With no public PoC or known in-the-wild exploitation, patching is precautionary rather than urgent. | 7.0 | — |
| mass≈150 million consoles (Nintendo's cumulative Switch hardware sales) |