Skip to content
Time to Patch: Nintendo Switch Can Be Hacked Using QR Codes

Time to Patch: Nintendo Switch Can Be Hacked Using QR Codes

Au.Pcmag • September 14, 2026

Nintendo is warning a security flaw in the first-gen Switch console related to the feature that lets you send game screenshots to a smartphone. It turns out you can hack the function to run malicious computer code or leak console data. Nintendo has issued a security advisory the vulnerability. It involves the Send to Smartphone function , which displays a QR code on the handheld that a smartphone can scan to initiate the wireless transfer of a game screenshot or in-game footage. According to Nintendo, unnamed security researchers recently discovered a way to exploit QR codes to carry out a Proximity-Based Remote Attack. “If a third party can directly scan the QR code, they could run unauthorized code on your Nintendo Switch console or obtain information stored on the console,” the advisory says. The vulnerability can also be exploited with the displayed QR code when pairing the kart accessory to play Mario Kart Live: Circuit. Details the bug, dubbed CVE-2026-82079, are thin. But it involves a “stack-based buffer overflow ,” where data copied into a memory buffer exceeds the buffer's size, overwriting adjacent memory and potentially leading to software crashes or a path to hack the system. Fortunately, exploiting the flaw isn't easy since the hacker would need to be nearby. Nintendo also patched the issue last week with version 23.0.0. So, it's recommended that users download and install the update. “You can check the current system version applied to your Nintendo Switch. From the , select System Settings > System . You can also update the system version,” the company says. Nintendo adds that “this vulnerability cannot be exploited to obtain console information on Nintendo Switch 2,” which seems to have phased out QR codes in favor of transferring screenshot via the Nintendo app.

Nintendo has issued a security advisory the vulnerability. It involves the Send to Smartphone function , which displays a QR code on the handheld that a smartphone can scan to initiate the wireless transfer of a game screenshot or in-game footage. According to Nintendo, unnamed security researchers recently discovered a way to exploit QR codes to carry out a Proximity-Based Remote Attack. “If a third party can directly scan the QR code, they could run unauthorized code on your Nintendo Switch console or obtain information stored on the console,” the advisory says. The vulnerability can also be exploited with the displayed QR code when pairing the kart accessory to play Mario Kart Live: Circuit. Details the bug, dubbed CVE-2026-82079, are thin. But it involves a “stack-based buffer overflow ,” where data copied into a memory buffer exceeds the buffer's size, overwriting adjacent memory and potentially leading to software crashes or a path to hack the system. Fortunately, exploiting the flaw isn't easy since the hacker would need to be nearby. Nintendo also patched the issue last week with version 23.0.0. So, it's recommended that users download and install the update. “You can check the current system version applied to your Nintendo Switch. From the , select System Settings > System . You can also update the system version,” the company says. Nintendo adds that “this vulnerability cannot be exploited to obtain console information on Nintendo Switch 2,” which seems to have phased out QR codes in favor of transferring screenshot via the Nintendo app.

According to Nintendo, unnamed security researchers recently discovered a way to exploit QR codes to carry out a Proximity-Based Remote Attack. “If a third party can directly scan the QR code, they could run unauthorized code on your Nintendo Switch console or obtain information stored on the console,” the advisory says. The vulnerability can also be exploited with the displayed QR code when pairing the kart accessory to play Mario Kart Live: Circuit. Details the bug, dubbed CVE-2026-82079, are thin. But it involves a “stack-based buffer overflow ,” where data copied into a memory buffer exceeds the buffer's size, overwriting adjacent memory and potentially leading to software crashes or a path to hack the system. Fortunately, exploiting the flaw isn't easy since the hacker would need to be nearby. Nintendo also patched the issue last week with version 23.0.0. So, it's recommended that users download and install the update. “You can check the current system version applied to your Nintendo Switch. From the , select System Settings > System . You can also update the system version,” the company says. Nintendo adds that “this vulnerability cannot be exploited to obtain console information on Nintendo Switch 2,” which seems to have phased out QR codes in favor of transferring screenshot via the Nintendo app.

Details the bug, dubbed CVE-2026-82079, are thin. But it involves a “stack-based buffer overflow ,” where data copied into a memory buffer exceeds the buffer's size, overwriting adjacent memory and potentially leading to software crashes or a path to hack the system. Fortunately, exploiting the flaw isn't easy since the hacker would need to be nearby. Nintendo also patched the issue last week with version 23.0.0. So, it's recommended that users download and install the update. “You can check the current system version applied to your Nintendo Switch. From the , select System Settings > System . You can also update the system version,” the company says. Nintendo adds that “this vulnerability cannot be exploited to obtain console information on Nintendo Switch 2,” which seems to have phased out QR codes in favor of transferring screenshot via the Nintendo app.

Fortunately, exploiting the flaw isn't easy since the hacker would need to be nearby. Nintendo also patched the issue last week with version 23.0.0. So, it's recommended that users download and install the update. “You can check the current system version applied to your Nintendo Switch. From the , select System Settings > System . You can also update the system version,” the company says. Nintendo adds that “this vulnerability cannot be exploited to obtain console information on Nintendo Switch 2,” which seems to have phased out QR codes in favor of transferring screenshot via the Nintendo app.

Nintendo adds that “this vulnerability cannot be exploited to obtain console information on Nintendo Switch 2,” which seems to have phased out QR codes in favor of transferring screenshot via the Nintendo app.

Extracted Entities

Attack Types (1)

Companies (1)