Owners of the original Nintendo Switch should patch a security exploit immediately, especially if they game in public. Nintendo announced the vulnerability (PDF) on Sept. 10, shortly after releasing its latest 23.0.0 firmware update.
The exploit applies only to original Nintendo Switch owners using the Send to Smartphone feature. This feature generates a QR code on the Switch that you can scan with a smartphone, letting you transfer game captures and screenshots directly to your phone.
It also affects people playing Super Mario Kart: Home Circuit on the physical cartridge, as the game uses a QR code to establish a wireless link with nearby players.
Should someone else scan the QR code before you, they can connect their device to your Switch and use the connection to run unauthorized code on your Switch or steal information stored on the game console. Since your account information is stored on your Switch, that’s information you don’t want in the hands of someone else.
A Nintendo representative did not immediately respond to a request for further comment.
The exploit does not affect the Nintendo Switch 2.
How to fix the problem
The fix is pretty simple. Nintendo released update 23.0.0 on Sept. 9, which fixes the exploit. It’s recorded as CVE-2026-82079, which is “a stock-based buffer overflow vulnerability” that lets attackers within wireless range execute code. It only affects the original Switch on firmware versions older than 23.0.0.
To update your Nintendo Switch, head to System Settings > System > System Update to apply the update. Follow any additional on-screen prompts to install the update.
Nintendo says that those who can’t immediately update their firmware can avoid the issue by only using the Send to Smartphone feature at home, where attackers can’t see them, or by not playing Super Mario Kart: Home Circuit in public. The gaming giant also recommends not scanning any QR codes with any device that isn’t yours.
... continue reading