Stack-based buffer overflow in Nintendo Switch local wireless networking enables unauthorized code execution

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-82079?

CVE-2026-82079 is a vulnerability classified as Stack-based Buffer Overflow, affecting Nintendo Switch (affected versions: < 23.0.0). This vulnerability is rated High, with a CVSS score of 7. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.

Affected products and scope

  • Nintendo Switch: the affected record marks versions from 0 through less than 23.0.0 as affected; default_status is set to unaffected outside the marked range.
  • Confirmed scenarios: use of Send to Smartphone in Album or use of a kart in Mario Kart Live: Home Circuit when a third party can directly scan the QR code displayed on the Nintendo Switch console or TV screen.
  • Nintendo Switch 2: Nintendo's advisory states that the vulnerability cannot be exploited to obtain console information on Nintendo Switch 2. This should not be expanded into a claim that every possible impact on every Nintendo Switch 2 function has been ruled out.

Technical details

This is a CWE-121 stack-based buffer overflow in the Nintendo Switch local wireless networking functionality. According to the record, an attacker within wireless range can send crafted network traffic and use return-oriented programming (ROP) to achieve arbitrary code execution. Nintendo confirms the vulnerability in limited scenarios involving the Send to Smartphone feature in Album and use of a kart in Mario Kart Live: Home Circuit; the attacker must directly scan the QR code displayed on the console or TV screen. Nintendo states that the vulnerability cannot be exploited in those scenarios when a third party cannot scan the displayed QR code. The public record does not identify the vulnerable function, packet structure, memory layout, or exact trigger sequence, so those implementation details remain unknown.

Exploitability

The vulnerability is reachable from wireless proximity and does not require privileges according to the supplied assessment data. User interaction is not fully absent: in the scenarios confirmed by Nintendo, the attacker must be able to directly scan a QR code shown on the console or TV screen. The named scenarios are Send to Smartphone in Album and use of a kart in Mario Kart Live: Home Circuit. The supplied record does not identify a public exploit, and its known_exploited field does not confirm observed exploitation.

Technical impact

The flaw can result in arbitrary code execution on Nintendo Switch when the reachability and QR-code scanning conditions are met. Nintendo states that a third party could run unauthorized code or obtain information stored on the console. This could undermine system software and local data integrity and may affect device availability, but the record does not describe the level of control obtained after code execution. The confirmed scope is limited to specific usage scenarios and not to every form of local wireless activity.

Business impact

  • An affected console may run unauthorized code if an attacker is within wireless range and meets Nintendo's QR-code scanning condition.
  • The advisory describes possible unauthorized code execution on the console or access to information stored on it.
  • For organizations managing multiple consoles, the primary concerns are loss of device integrity and possible exposure of locally stored data on systems that have not been updated.
  • The advisory identifies limited confirmed scenarios but does not provide evidence of a specific incident, victim, or attack campaign.

Remediation

  1. Perform System Update 23.0.0 on the Nintendo Switch. This is the fixed release stated in the record's solution.
  2. Verify the installed version from the HOME Menu by selecting System Settings, then System; Nintendo also provides system software update controls there.
  3. If updating cannot be performed immediately, when using Send to Smartphone in Album or a kart in Mario Kart Live: Home Circuit, ensure that third parties cannot view or scan the QR code displayed on the console or TV screen.
  4. Do not use a smart device other than the user's own device with Send to Smartphone, and do not use another person's kart with Mario Kart Live: Home Circuit, following Nintendo's stated precautions.

Detection

  • Inventory Nintendo Switch consoles and check the current system software version; identify systems that remain within the affected range stated in affected_summary.
  • Identify consoles using Send to Smartphone in Album or a kart in Mario Kart Live: Home Circuit, because Nintendo specifically names these scenarios.
  • Review console and TV placement to ensure unauthorized people cannot view or scan QR codes displayed during those features.
  • The supplied record and advisory do not provide log events, IOCs, or network signatures. Absence of such evidence does not prove that a device is safe; version and usage-condition checks are the primary verification steps.
Sources (14)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan