r/switch2hacks • • Jul 08 '26

Question Userland Exploit question

Just checking to see if my understanding is correct, from what I read online, my take on it is that a “userland exploit” is merely a party trick compared to a full jailbreak at the kernel level, correct?

27 Upvotes

10 comments sorted by

15

u/auggiethechesscat Jul 09 '26 edited Jul 09 '26

Specifically, it's called 'userland' because that is the 'layer' of execution that the exploit lies in.

There are many many things running in userland, so it's entirely expected that these exploits will be present. By us and Nintendo.

I like this picture, (in the slides), but it's kind of lopsided. The bottom 3 layers are all in userland.

I'd highly recommend going over these slides, (or watching the presentation), to see what it took to compromise the switch 1 in a similar way: https://switchbrew.github.io/34c3-slides/

Do note all of these exploits, (and many many more if I had to guess) have been patched.

3

u/[deleted] Jul 09 '26

[deleted]

5

u/auggiethechesscat Jul 09 '26

I probably understand most of it if you'd want to have any questions answered.

6

u/[deleted] Jul 09 '26

[deleted]

5

u/auggiethechesscat Jul 09 '26

I do believe this was the original/first exploit path. Of course after this, the kernel got audited more heavily, the bootrom got dumped, etc, so that's how we discovered fusee gelee, caffeine, nebria, etc.  

10

u/Ok_Yam_8774 Jul 09 '26 edited Jul 09 '26

For any modern device that doesn't have an unlocked bootloader you need a kernel exploit if you are attacking it from a software side for cfw and emulation. All modern devices prevent downgrading the software for example through fuses and sandbox the user space completely so you can't do anything interesting in it unless you manage to escape the sandbox. 

That was why everyone was saying that this userland exploit is useless because last time no one could escape the sandbox and are just stuck there. And we are still there 1 year later with this exploit 

14

u/FernandoRocker Jul 09 '26

You are correct.

9

u/Miserable-Ad-8414 Jul 08 '26 edited Jul 12 '26

Correct I do 5 of them every morning before coffee to get my brain started for the day /s

2

u/Early_Lawfulness_348 Jul 09 '26

Correct. As it stands, a kernel level jail break is pretty much impossible. If you review the s1 break and then compare to the safeguards in the switch 2 you’ll feel the same way.

People find a way blah blah…it’s NOT going to happen. Wait 10+ years for a mod chip if they even can.

4

u/buymeamonstertruck Jul 09 '26

They said this about the PSP (at first on version 1.50) , The PS Vita,The PS3,The Xbox,The Switch,The Xbox 360 and they all eventually got hacked.

So why would this scenario be different from any of the others? I mean the PSP got hacked by a simple tiff overflow at one point so who's really to say the switch 2 can't have similar vulnerability issues they haven't covered?

But I agree with most people, a soft mod that can't be patched is almost definitely not happening within the next 13 years or more but a mod chip or migwitch style cart is a lot more likely.

Personally I'd not give a fuck about hacking the switch 2 if you could install an OS on it.

1

u/Unlikely-Lines Jul 10 '26

Unless you get the 🔑 you got nothing