If you own an original Nintendo Switch, there’s a security exploit you will want to patch immediately, especially if you use the game console in public. Nintendo revealed the vulnerability on Sept. 10, shortly after the company released its latest 23.0.0 firmware update.
The vulnerability applies only to original Nintendo Switch owners who use the Send to Smartphone feature. This feature generates a QR code on the Switch that users can scan with a smartphone, allowing them to transfer game captures and screenshots directly to their phone.
The exploit also affects people playing Super Mario Kart: Home Circuit on the physical cartridge, as the game uses a QR code to establish a wireless link with nearby players.
Should someone else scan the QR code before you, they can connect their device to your Switch and use the connection to run unauthorized code on your Switch or steal information stored on the game console. Since your account information is stored on your Switch, that’s information you don’t want in the hands of someone else.
A Nintendo representative did not immediately respond to a request for further comment.
The fix is simple. Nintendo released update 23.0.0 on Sept. 9, which fixes the exploit. It’s recorded as CVE-2026-82079, which is “a stock-based buffer overflow vulnerability” that lets attackers within wireless range execute code. It only affects the original Switch on firmware versions older than 23.0.0.
To update your Nintendo Switch, head to System Settings > System > System Update to apply the update.
Source link







