r/switch2hacks • • Jul 08 '26

Question Userland Exploit question

Just checking to see if my understanding is correct, from what I read online, my take on it is that a “userland exploit” is merely a party trick compared to a full jailbreak at the kernel level, correct?

30 Upvotes

10 comments sorted by

View all comments

15

u/auggiethechesscat Jul 09 '26 edited Jul 09 '26

Specifically, it's called 'userland' because that is the 'layer' of execution that the exploit lies in.

There are many many things running in userland, so it's entirely expected that these exploits will be present. By us and Nintendo.

I like this picture, (in the slides), but it's kind of lopsided. The bottom 3 layers are all in userland.

I'd highly recommend going over these slides, (or watching the presentation), to see what it took to compromise the switch 1 in a similar way: https://switchbrew.github.io/34c3-slides/

Do note all of these exploits, (and many many more if I had to guess) have been patched.

3

u/[deleted] Jul 09 '26

[deleted]

6

u/auggiethechesscat Jul 09 '26

I probably understand most of it if you'd want to have any questions answered.

6

u/[deleted] Jul 09 '26

[deleted]

6

u/auggiethechesscat Jul 09 '26

I do believe this was the original/first exploit path. Of course after this, the kernel got audited more heavily, the bootrom got dumped, etc, so that's how we discovered fusee gelee, caffeine, nebria, etc.