
Nintendo has patched a high-severity Nintendo Switch vulnerability that could allow a nearby attacker to execute unauthorized code or access information stored on the console.
The flaw, tracked as CVE-2026-82079, affects Switch systems running firmware versions earlier than 23.0.0 and is exposed in limited scenarios involving QR codes and local wireless networking.
Nintendo disclosed the vulnerability on September 10 after it was reported by unnamed external security researchers. According to the company, exploitation requires an attacker to directly scan a QR code displayed on the Switch or a connected TV while the owner is using the Album’s “Send to Smartphone” feature or a kart in Mario Kart Live: Home Circuit.
The CVE description provides additional technical detail, identifying the issue as a stack-based buffer overflow in the Nintendo Switch local wireless networking functionality. An attacker within wireless range can reportedly send specially crafted network traffic that triggers the overflow and use return-oriented programming (ROP) to execute arbitrary code.
Nintendo is the Japanese video game company behind the Switch console family and franchises including Mario, Zelda, and Pokémon. The original Nintendo Switch launched in 2017 and has since become one of the company’s core gaming platforms. Nintendo says CVE-2026-82079 cannot be exploited to obtain console information from the newer Nintendo Switch 2.
Nintendo says the vulnerability cannot be exploited under the documented scenarios when a third party cannot view and scan the QR code shown by the console. However, if an attacker can scan it, the company warns that they may be able to run unauthorized code or retrieve information stored on the device.
Nintendo addressed the issue in Switch system update 23.0.0. Users can check their installed firmware under System Settings > System and should install the latest update as soon as possible.
Those unable to update immediately should avoid exposing QR codes generated by the affected features to other people. Nintendo also recommends using only the owner’s smartphone with “Send to Smartphone” and only the owner’s kart when playing Mario Kart Live: Home Circuit, reducing opportunities for an untrusted nearby device to interact with the vulnerable local wireless functionality.







Leave a Reply