Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-82079 Vulnerabilities

Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Code Feature

Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could allow a nearby attacker to execute unauthorized code or access information stored on the console.

Tracked as CVE-2026-82079, the vulnerability affects Nintendo Switch systems running firmware versions earlier than 23.0.0 and originates from a stack-based buffer overflow in the console's local wireless networking functionality.

Nintendo addressed the security issue with system version 23.0.0, released in September 2026.

CVE-2026-82079 at a Glance

Detail Information
CVE CVE-2026-82079
Product Nintendo Switch
Vulnerability Stack-based buffer overflow
Component Local wireless networking
Severity High
CVSS v4.0 7.0
CVSS v3.1 8.4
Affected versions Earlier than 23.0.0
Fixed version 23.0.0
Switch 2 affected No, according to Nintendo's advisory

The vulnerability can potentially allow an attacker within wireless range to send specially crafted network traffic and execute arbitrary code using return-oriented programming (ROP).

Attack Involves Nintendo's QR Code Workflow

CVE-2026-82079 cannot simply be exploited remotely against any Nintendo Switch connected to the internet.

Nintendo says exploitation is limited to specific scenarios involving local wireless communication and QR codes.

The affected workflows include the Send to Smartphone feature available through the Nintendo Switch Album and the local connectivity used by Mario Kart Live: Home Circuit.

During these operations, the Switch displays a QR code on the console or connected television.

A nearby third party would need to directly scan that displayed QR code while remaining within wireless range of the console.

The attack sequence can be summarized as:

User activates an affected feature → Switch displays QR code → Nearby attacker scans displayed QR code → Attacker establishes local wireless interaction → Crafted network traffic reaches vulnerable functionality → Stack buffer overflow triggered → Unauthorized code execution becomes possible

The QR code itself is therefore not malicious. Rather, it facilitates the local wireless connection that can expose the vulnerable networking functionality.

What Could an Attacker Do?

Successful exploitation could allow an attacker to execute unauthorized code on the affected Nintendo Switch.

Nintendo also warns that exploitation could potentially allow a third party to obtain information stored on the console.

Because the underlying vulnerability involves memory corruption, technical vulnerability records indicate that crafted network traffic could be used to manipulate execution through return-oriented programming.

However, the practical attack requirements substantially limit the opportunities for exploitation.

An attacker must be physically nearby, within wireless range and able to scan the QR code displayed by the victim's console or television.

This makes CVE-2026-82079 considerably different from an internet-exploitable vulnerability that could be remotely scanned and attacked at scale.

Nintendo Switch 2 Is Not Affected in the Same Way

Nintendo's advisory applies to the original Nintendo Switch family and states that the vulnerability cannot be exploited to obtain console information from Nintendo Switch 2 through this scenario.

Owners of the original Switch should therefore pay particular attention to their installed firmware version.

Nintendo Releases Firmware 23.0.0

Nintendo fixed CVE-2026-82079 through Nintendo Switch system version 23.0.0.

The update was released in September and includes the vulnerability fix alongside other system changes and stability improvements.

Users can check their installed version and manually update by navigating to:

HOME Menu → System Settings → System → System Update

Nintendo Switch consoles connected to the internet will normally download available system updates automatically.

What Users Should Do

Nintendo strongly recommends updating affected consoles to system version 23.0.0 or later.

Users who cannot immediately install the update should prevent other people from scanning QR codes displayed by the console or television when using the affected functionality.

Nintendo also recommends using only the owner's trusted smartphone with the Album's Send to Smartphone feature and avoiding unfamiliar karts when using Mario Kart Live: Home Circuit.

No Evidence of Widespread Exploitation

Current public information does not indicate widespread exploitation of CVE-2026-82079 in the wild.

The vulnerability's attack requirements also make opportunistic exploitation relatively difficult because an attacker needs proximity to the console and interaction with a specific local wireless workflow.

Nevertheless, the ability to potentially execute unauthorized code makes the flaw significant enough that Nintendo recommends installing the available security update.

Security Takeaway

CVE-2026-82079 demonstrates that gaming consoles can face many of the same memory-safety and networking risks found in traditional computing platforms.

What makes this vulnerability particularly interesting is its unusual attack path. The attacker does not simply send a malicious QR code to the Switch. Instead, the legitimate QR code generated by the console helps establish a local wireless connection, after which specially crafted network traffic can target the vulnerable networking component.

The requirement for close proximity reduces the likelihood of mass exploitation, but successful exploitation could still result in unauthorized code execution or exposure of information stored on an affected console.

Nintendo Switch owners should therefore ensure they are running firmware 23.0.0 or later and avoid exposing QR codes generated by affected features to untrusted people until the console has been updated.

SEO Meta Description:
Nintendo patched CVE-2026-82079, a high-severity Switch vulnerability that lets nearby attackers potentially execute unauthorized code through local wireless QR code workflows.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

critical CVE-2026-5430 Vulnerabilities

Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens

Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.

critical CVE-2026-85046, CVE-2026-87491 and CVE-2 Vulnerabilities

China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor

China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.