ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Nintendo Patches Switch QR-Code Stack Buffer Overflow (CVE-2026-82079) Allowing Nearby Code Execution

mediumVulnerabilityimportance 40CVE-2026-82079
What's new: Initial merged summary created from two reports (Cyber Security News, 2026-09-14; GBHackers, 2026-09-15). Both reports consistently cover CVE-2026-82079, the QR-code-mediated stack buffer overflow, the 23.0.0 fix, and Switch 2 being unaffected. GBHackers added the CVSS 3.1 score of 8.4 alongside the shared v4.0 score of 7.0 and confirmed no in-the-wild exploitation; Cyber Security News…
Merged summary · glm-5.3 · rewritten as coverage arrives

Nintendo fixed CVE-2026-82079, a stack buffer overflow in original Switch local wireless networking, in system update 23.0.0; a nearby attacker who scans the console's displayed QR code could achieve arbitrary code execution.

Nintendo Switch system update 23.0.0 patches CVE-2026-82079, a stack-based buffer overflow in the original Switch's local wireless networking. Exploitation requires an attacker in wireless proximity who scans a QR code displayed by the console — via the Album 'Send to Smartphone' feature or Mario Kart Live: Home Circuit pairing — after which crafted packets can corrupt memory and enable return-oriented programming for arbitrary code execution. Both sources agree the CVSS 4.0 base score is 7.0 (High); GBHackers additionally reports a CVSS 3.1 score of 8.4 (also High), while Cyber Security News does not cite a v3.1 score. Only firmware versions earlier than 23.0.0 are affected, and Switch 2 consoles are not vulnerable. Cyber Security News reports an EPSS of approximately 0.16% (low 30-day exploitation forecast) and dates Nintendo's advisory to September 10, 2026; GBHackers reports no in-the-wild exploitation, malware payloads, or campaigns observed.

  • CVE-2026-82079 is a stack-based buffer overflow in the original Nintendo Switch's local wireless networking.
  • Fixed in Nintendo Switch system update / firmware 23.0.0; affects firmware earlier than 23.0.0.
  • Exploitation requires wireless proximity plus the attacker scanning a QR code displayed by the console via Album's 'Send to Smartphone' feature or Mario Kart Live: Home Circuit, followed by crafted packets and return-oriented programming…
  • CVSS 4.0 base score 7.0 (High); GBHackers also reports CVSS 3.1 score 8.4 (High) — sources agree on the v4.0 figure.
  • EPSS approximately 0.16%, indicating a low 30-day exploitation forecast (per Cyber Security News).
  • Nintendo Switch 2 consoles are not affected.
  • No in-the-wild exploitation, malware payloads, or campaigns reported.
  • Nintendo's advisory was published September 10, 2026 (per Cyber Security News).

Coverage timeline

  1. · 1d ago
    Cyber Security News· 40
    Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console

    Nintendo patched CVE-2026-82079, a CVSS 7.0 stack buffer overflow in original Switch local wireless allowing nearby code execution via QR-code workflows.

  2. · 1d ago
    GBHackers· 35
    Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code

    Nintendo patched CVE-2026-82079 (CVSS 8.4), a stack buffer overflow in Switch local wireless pairing enabling nearby attackers to execute code.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82079
Stack Buffer Overflow in Nintendo Switch Local Wireless Enables Nearby-Attacker RCE

CVE-2026-82079 is a stack-based buffer overflow (CWE-121) in the Nintendo Switch's local wireless networking functionality, affecting system software versions before 23.0.0. An attacker who is physically within wireless range of a console can send crafted network traffic that overruns a stack buffer during local wireless communication. Using return-oriented programming (ROP), the attacker can achieve arbitrary code execution on the console, consistent with the high-impact (8.4) CVSS score covering confidentiality, integrity, and availability. All Nintendo Switch consoles running system software earlier than 23.0.0 are affected; exploitation requires close physical proximity rather than internet access. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update Nintendo Switch system software to 23.0.0 or later via System Settings > System > System Update; consoles connected to the internet typically download system updates automatically, but verify the installed version manually. Until updated, restrict local wireless (local multiplayer) play to trusted nearby users, since an attacker must be within wireless range and there is no internet-facing exposure. With no public PoC or known in-the-wild exploitation, patching is precautionary rather than urgent.

7.0
  • Nintendo Switch (system software) before 23.0.0
mass≈150 million consoles (Nintendo's cumulative Switch hardware sales)