NintendoNews report
Nintendo Identifies Security Exploit Allowing Code Execution or Information Access on Older Switch Models
Nintendo has issued a security advisory detailing an exploit that could enable unauthorized code execution or data retrieval from Nintendo Switch consoles via proximity-based remote attacks involving QR code scanning.

Nintendo published a security notice today describing a vulnerability in Switch systems that could allow a bad actor to run unauthorized code or obtain information stored on the console. The exploit is triggered when a QR code displayed on the Switch console screen—during Album's Send to Smartphone feature—or while playing Mario Kart Live: Home Circuit with a kart—is scanned by a nearby device. Affected Switch units are those running firmware prior to version 23.0.0. Importantly, Nintendo confirmed the vulnerability cannot be exploited against the upcoming Nintendo Switch 2. The company recommends updating all Switch systems to the latest version 23.0.0 through the HOME menu under System Settings. Until then, users should ensure their console is in an environment where third parties cannot scan the QR code, particularly when using Send to Smartphone or Mario Kart Live: Home Circuit features. No evidence indicates the issue affects newer hardware beyond the current Switch model line.
Further reading
Sources
- Nintendo EverythingEstablished publication · recorded Sep 10, 2026Nintendo identifies Switch exploit in which bad actor could run code or obtain information stored on the console
