Nintendo Warns Switch Owners of QR Code Exploit That Could Run Unauthorized Code and Access Console Data

Nintendo has warned Switch owners about a proximity-based vulnerability that could let an attacker run unauthorized code or access information stored on an affected console.

Thread

Nintendo reportedly targeted more than 400 Nintendo Switch emulator repositories in a coordinated GitHub DMCA sweep. (Image via Nintendo/GitHub)

Nintendo has disclosed a security vulnerability affecting Nintendo Switch systems running software older than version 23.0.0. The company says the issue is limited to specific situations involving QR codes displayed by the console, but successful exploitation could potentially allow a third party to execute unauthorized code or obtain information stored on the system.

The vulnerability, identified as CVE-2026-82079, requires physical proximity to the affected Nintendo Switch. Nintendo has already released a system update that addresses the issue, making updating the console the most important step for owners who may still be running older firmware.

Nintendo Switch Owners Should Update to Version 23.0.0

According to Nintendo’s official security notice, the vulnerability can be triggered when a third party directly scans a QR code displayed on the Switch console or its connected TV screen. The affected situations involve the Send to Smartphone function in the Album and the use of a kart with Mario Kart Live: Home Circuit.

Nintendo specifically warns that the vulnerability cannot be exploited if an unauthorized person cannot scan the displayed QR code. However, the company recommends updating rather than relying solely on this limitation, particularly when using either feature in public or around other people.

Nintendo Switch console affected by the newly disclosed security vulnerability (Image via Nintendo)

The affected systems are Nintendo Switch consoles running a version earlier than 23.0.0. Nintendo has confirmed that the vulnerability cannot be used to obtain console information from Nintendo Switch 2.

Nintendo’s security advisory identifies the issue as “Potential Nintendo Switch Console Information Leak Due to Proximity-Based Remote Attack.” The company also says the vulnerability was reported by external security researchers.

Nintendo recommends checking the system software by opening System Settings > System from the HOME Menu and selecting the system update option. Version 23.0.0 also includes other system changes, including new settings for Virtual Game Cards and general stability improvements.

Until an affected console is updated, Nintendo advises users to ensure that other people cannot scan the QR code shown on the console or TV. It also recommends avoiding someone else’s smart device when using Send to Smartphone and using only your own kart with Mario Kart Live: Home Circuit.

The security notice is available through Nintendo’s official security advisory page, which lists the vulnerability and recommended mitigation measures.

Verified since 2021 Senior Content Writer

Oliver Johnson is a Senior Content Writer at OtakuKart passionate about celebrity dating, with nearly 570 published articles. With a knack for storytelling, he crafts engaging articles that bring vibrant celebrity storylines to life, covering love-life features for stars like Millie Bobby Brown, Michael B. Jordan, Jennifer Lopez, and Emilia Clarke alongside Hollywood Net Worth deep dives.

THREAD

Share your take. All comments are held for review before appearing.

Be the first to share your thoughts.