CVE-2026-82079 PUBLISHED

Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack

Assigner: Nintendo
Reserved: 28.08.2026 Published: 10.09.2026 Updated: 10.09.2026

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.

Product Status

Vendor Nintendo
Product Nintendo Switch
Versions Default: unaffected
  • affected from 0 to 23.0.0 (excl.)

Workarounds

If you cannot update to the latest system version right away, please note the following when using the system.

  • When using the "Send to Smartphone" feature in Album or when using a kart in Mario Kart Live: Home Circuit, please ensure that the QR code displayed on the console screen (or on the TV screen) cannot be viewed or scanned by third parties.
  • Please refrain from using the "Send to Smartphone" feature in Album with a smartphone other than your own, and from using a kart other than your own in Mario Kart Live: Home Circuit.

Solutions

Perform System Update 23.0.0.

References

Problem Types

  • CWE-121 Stack-based buffer overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers