Nintendo Switch QR Code Flaw Could Allow Remote Code Execution
Do you use the "Send to Smart Device" feature to retrieve screenshots from your Nintendo Switch? Be aware that the QR code displayed on screen could serve as an entry point for an attacker nearby. While exploitation is still difficult in real-world conditions, Nintendo has released a fix.
A QR code as an entry point, but not a booby-trapped QR code
A new security flaw has been discovered in the system used by the Nintendo Switch. Its reference: CVE-2026-82079. As explained in the security advisory, this vulnerability could allow an attacker nearby the console to steal information. But be careful: exploitation is only possible in a specific scenario involving QR codes.
When I say QR code, you might think of quishing (QR code phishing), which would imply that the attacker distributes a malicious QR code that you then scan. That is not the case here: the mechanism is different. The problem is not a malicious QR code scanned by the victim, but the QR code generated by the console itself.
The Switch displays this code in two specific situations:
- The "Send to Smart Device" feature in the Album. It lets you transfer screenshots and videos to a phone through a local wireless network created by the console.
- Pairing a kart in Mario Kart Live: Home Circuit. The game uses the same principle to connect the physical kart to the console.
In both cases, the QR code is used to establish a local wireless link. An attacker who manages to scan this code (on your console screen or on the connected TV) can then join that link. That is where the flaw lies.
"A stack-based buffer overflow vulnerability in the local wireless networking feature of Nintendo Switch may allow an attacker within wireless range to execute arbitrary code, via specially crafted network traffic, using return-oriented programming (ROP)", reads the description of CVE-2026-82079.
In theory, an attacker able to scan your console's QR code could execute unauthorized code on the console or retrieve information stored on it. In other words: no QR code, no attack. In practice, the security issue is serious, but exploitation is complex.
How can you protect your Nintendo Switch?
In any case, the good news is that a fix is available: it has been included in system update 23.0.0 (dated September 10, 2026). I do not have a Nintendo Switch to walk you through the menus and check your console's version, but if it is connected to the Internet, the update is normally offered automatically.
Either way, if you do not use the vulnerable features mentioned in this article, you are not at risk. Let us be honest: the real-world risk depends on the context. At home in your living room, the risk is low (although you might still want to check behind the couch, just in case). On a train, in a waiting room, or at an event, perhaps, but still.
Here is a model-by-model summary of this security flaw:
| Model | Vulnerable? | Risks and notes |
|---|---|---|
| Nintendo Switch (2017) | Yes, if running a system version earlier than 23.0.0 | Unauthorized code execution or theft of information stored on the console, provided a third party scans the QR code displayed on the console screen or on the TV. Model mentioned in Nintendo's advisory. |
| Nintendo Switch Lite | Very likely yes, if running a system version earlier than 23.0.0 | Not mentioned in Nintendo's advisory, but it runs the same system as the Switch and received the same 23.0.0 update. Slightly smaller attack surface: no TV output, so the QR code is only visible on the console screen. |
| Nintendo Switch OLED model | Very likely yes, if running a system version earlier than 23.0.0 | Same situation as the Lite on the sourcing side (not mentioned, same system, same update). Same risk as the original Switch, including QR code display on the TV via the dock. |
| Nintendo Switch 2 | No, according to Nintendo | Here, Nintendo's wording is more cautious, as it states that the flaw cannot be exploited to obtain information from the console on this model. It would not be affected. |


