Nintendo warns Switch QR code exploit could hack console and issues firmware update

Nintendo is urging Switch console owners to upgrade to firmware version 23.0.0. The company issued a bulletin after discovering the handheld was at risk of a “proximity-based remote attack.” QR codes generated by the Album feature and the Mario Kart Live: Home Circuit racing game expose the vulnerability.
When browsing screenshots and gameplay clips, gamers can transfer the content to smartphones. In the process, a QR code appears on the console, which mobile devices scan to communicate with the gaming system. However, before the firmware update, nefarious individuals could have potentially run unauthorized code on the Switch.

The gaming giant explains that, alternatively, the hack identified as CVE-2026-82079 could result in stolen data. Owners of the Mario Kart Live: Home Circuit system may also be a target. In the game, the console steers the camera-mounted Mario or Luigi karts around households. Once again, the handheld displays a barcode to establish the wireless link.
For most users, the scenarios in which the QR exploit is a realistic concern are limited. Nevertheless, gamers without an internet connection may not be able to update the Switch console’s firmware. For those individuals, Nintendo advises against sharing Album media or linking to the karts around strangers.
A more secure Switch 2
The company doesn’t detail the consequences of a hacker running unauthorized code. Fortunately, the Switch 2 doesn’t suffer from the same vulnerability. The more recent system also saw a host of new features added with the 23.0.0 firmware. Curiously, gamers can generate QR codes to share their Miis with friends and family for the first time.
The change that’s receiving the most attention addresses a shortcoming of docked mode. Previously, the Switch 2 lacked VRR compatibility when outputting video to TVs. Now, in supported games, players should experience less stuttering when frame rates fluctuate.




















