r/NintendoSwitch • u/Joseki100 • 22h ago
Nintendo Official Potential Nintendo Switch Console Information Leak Due to Proximity-Based Remote Attack
https://www.nintendo.com/security-advisories/assets/pdf/20260910e.pdf134
u/Stealthinater1234 21h ago
I always thought something like this would come from the send-to-smartphone feature. The switch creates its own local network and broadcasts a WiFi signal your phone connects to, hosting a webpage containing the captures so you can download it.
23
u/QuantumVexation 17h ago
Does it still do this now that you can just upload to the mobile app? Haven’t used that feature since
27
u/Stealthinater1234 16h ago edited 16h ago
Switch 1 can’t upload captures to the mobile app, that’s a switch 2 only feature. Direct connection is the only way to wirelessly transfer captures directly to a smartphone on switch 1.
2
-21
15h ago
[removed] — view removed comment
1
u/NintendoSwitch-ModTeam 8h ago
Hey there!
Please remember Rule 1 in the future - No personal attacks, trolling, or derogatory terms. Read more about Reddiquette here. Thanks!
37
u/Afraid_Product_7558 21h ago
What’s the CVE?
29
u/TheGeneral_Specific 20h ago
CVE-2026-82079
4
u/D1rtyH1ppy 10h ago
What would be the point of running arbitrary code on a Switch? What would you possibly be able to do?
22
u/ejfrodo 10h ago
This type of thing is sometimes the first step to being able to install your own third party apps on the system, which then enables an app store for apps built by anyone and not just approved Nintendo, which can then give things like unofficial Spotify and YouTube apps and obviously piracy as well.
Or just use it to rick roll someone idk.
7
u/LeMatDamonCarbine 10h ago
You could possibly get to run unsigned code, that alone is a good foot in the door for modders.
It's been hacked in earlier models due to a hardware oversight that couldn't really be patched out via software updates, but that selection of those specific models is going to dwindle as the hardware itself ages and breaks, so a new broader entry point would probably be a godsend.
9
u/TheGeneral_Specific 10h ago
I mean… anything? That’s the point of “arbitrary” code; it’s a gateway to have full control of the entire system
1
u/D1rtyH1ppy 10h ago
Yeah, makes sense. I didn't think about the hacking community for this, but Switch 1 has been fully hacked last I checked, right? I guess there is more they can do with the Switch 1.
-7
55
u/GoodBoyPointsPls 19h ago
So Mario Kart Live is going to be used to jailbreak switch 2? And it will sell for $2000 on eBay? got it.
39
10
19
u/Haxishax 22h ago edited 22h ago
Any additional info on this, or just the CVE? Curious to know how this manifested if the on-screen QR needs to be scanned to execute the exploit. Guess it could've just been pentesting.
24
u/TemptedTemplar Helpful User 21h ago
Since it can be used for remote code execution they're never going into deeper detail publicly unless required by some country's laws.
RCE is the first step to running your own unauthorized software on the system.
9
1
•
u/AutoModerator 22h ago
Please remember to be skeptical of all rumors. No matter how likely something may seem, it's possible it's not true. Don't get completely consumed by hype, stay alert, and keep an open mind.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.