GAMING
Nintendo Patches the Switch QR Code Used to Share Screenshots
Firmware 23.0.0 closes a Switch QR pairing bug that opened local wireless to a nearby attacker, while Switch 2 already moved screenshots onto Nintendo’s servers.
Nintendo patched a Switch QR code flaw in firmware 23.0.0 that let a nearby attacker run unauthorized code after scanning the screen. The hole sat in the original console’s local share path, not in a remote internet service.
On September 10, 2026, Nintendo posted a September 10 proximity attack security notice covering two everyday features that draw a QR code on the console or a TV: Album’s Send to Smartphone tool, and pairing for Mario Kart Live: Home Circuit. Scan that code from the wrong phone, and the session behind it can be abused.
The Original Switch Shared Photos Through a Screen QR Code
For most of the original Switch’s life, getting a screenshot onto a phone meant standing in front of the console and scanning a code. Nintendo did not push those images to an account in the background. The Switch opened a short-range wireless hop, the phone joined it, and the files moved across the room.
That design kept the transfer off Nintendo’s servers. It also put a live pairing target on the screen, including on a docked TV, for as long as the code stayed up. Official support for the original hardware still describes a wireless send of up to 10 screenshots and one video in a single pass.
Switch 2 dropped that hop. Screenshots and clips go to the Nintendo Switch App through Nintendo’s servers, tied to a Nintendo Account, and they sit there for 30 days with a cap of 100 files. A paid Nintendo Switch Online plan is not required. Automatic uploads can run from the Album’s upload settings, so the phone never has to see a code on the glass.
SWITCH AND SWITCH 2 SHARE PATHS
| Step | Original Switch | Switch 2 |
|---|---|---|
| How files leave the console | Scan a QR code and join a local wireless session | Upload to the Nintendo Switch App |
| How many files | Up to 10 screenshots and one video per send | Up to 100 files held for 30 days per account |
| Account needed | No Nintendo Account for the QR hop | Nintendo Account; no paid Online plan |
| Named in CVE-2026-82079 | Yes, on system versions before 23.0.0 | Cannot be used to obtain console information |
The original path looked like the private option because nothing had to hit a Nintendo login. The CVE now sitting on that path is the cost of keeping the handshake local, visible, and easy to point a camera at.
Mario Kart Live Puts That Code on the Living Room TV
The second surface is older toy hardware, not a social feature. Mario Kart Live: Home Circuit pairs a camera-mounted kart to the Switch by showing a QR code in the game. Nintendo’s own pairing steps tell you to start the software, press the kart’s ignition button, then aim the kart camera at the QR code on the console or the TV until the lights settle.
Once that pair is stored, later sessions can reconnect without scanning again. A kart that was paired to a different Switch needs a fresh scan, which puts the code back on the screen. In TV mode the code is large enough that Nintendo’s troubleshooting pages tell people to switch to handheld if the kart cannot read it, which is another way of saying the living-room display is doing the work.
WHEN THE KART ASKS FOR A CODE
- First pair: The game draws a QR code and the kart camera has to capture it from the Switch screen or the TV.
- Later play: A kart already tied to that console can reconnect after a short ignition press, without a new scan.
- New console: Pointing the same kart at a different Switch brings the QR code back so the pair can be rewritten.
- Docked play: The code can sit on the television, which is the surface a guest phone can see as easily as the kart can.
That is a children’s toy that needs a bright, lingering code in a shared room. Nintendo named this game beside Send to Smartphone for a reason: the attacker does not need the owner’s phone, only a camera that can see the same square the kart is supposed to read.
What CVE-2026-82079 Does to a Nearby Switch
The consumer notice talks about QR codes because that is the moment a second device is invited onto the console’s local network. The bug Nintendo filed is one layer down. A stack-based buffer overflow scored 7.0 sits in the original Switch’s local wireless networking, and a nearby attacker can try to run code by sending crafted traffic that reuses pieces of software already on the console, a method the record names as return-oriented programming.
CVE-2026-82079 AT A GLANCE
- Score: 7.0 High on CVSS 4.0, with adjacent-network access and user interaction required.
- Weakness: CWE-121, a stack-based buffer overflow.
- Range: An attacker has to be within wireless range, not on the open internet.
- Product: Nintendo Switch system versions before 23.0.0; Nintendo says the issue cannot be exploited to obtain console information on Switch 2.
The vector spells out the limits. AV:A means the attacker is on the local radio, not across the web. UI:P means the owner has to present the QR. PR:N means the attacker does not need an account on the Switch. Integrity impact is high, which is the line that covers unauthorized code. Confidentiality and availability sit lower, which matches a notice that talks about stored information without claiming a full remote takeover from another country.
If a third party can directly scan the QR code, they could run unauthorized code on your Nintendo Switch console or obtain information stored on the console.
Nintendo, Security Notice for Nintendo Switch, September 10, 2026
The same notice says the bug cannot be used in a place where nobody else can scan the screen. Outside researchers who reported the issue are not named. Nintendo also warns that wording in its security posts may be left vague on purpose so the notice does not double as a how-to.
Version 23.0.0 Closes the Hole on the Original Switch
The fix is the system version, not a separate game patch. Nintendo’s notice tells owners to move to 23.0.0, and the CVE record marks every earlier Switch system version as affected. GitHub mirrors of the official firmware package timestamp the 23.0.0 dump on September 10, 2026, the same calendar date as the consumer notice.
THE WEEK THE CVE LANDED
- January 13, 2026: The CVE Program lists Nintendo Co., Ltd. as a numbering authority for Switch family system bugs and for Nintendo-published games on those systems.
- September 9, 2026: CVE-2026-82079 is published at 19:56 UTC, with Nintendo as the CNA.
- September 10, 2026: Firmware 23.0.0 ships and Nintendo posts the proximity-based remote attack notice, including the two QR scenarios and the Switch 2 caveat.
On Switch 2, version 23.0.0 is a feature drop. Docked VRR support, a Handheld Mode Boost toggle, system transfer between Switch 2 consoles, and a Mii QR share option all landed under that number. Original Switch notes for the same version are thinner, with Virtual Game Card settings and stability fixes beside the security close.
The split is the tell. Switch 2 never used the Album QR hop, so its 23.0.0 story is refresh rates and Mii codes. The original hardware still had to patch the wireless stack that those QR sessions opened. People following the update on the new console treated 23.0.0 as a feature list. The CVE was a footnote on a machine Nintendo had already moved off that path.
Nintendo Assigned This Bug Under Its Own CNA
Until this year, a Switch system hole would have been numbered by someone else. On January 13, 2026, the CVE Program added Nintendo as a CVE Numbering Authority for system vulnerabilities on Switch 2, Switch, and Switch Lite, plus games Nintendo publishes on those platforms. Nintendo is the 14th CNA from Japan, under the JPCERT/CC root.
CVE-2026-82079 carries Nintendo Co., Ltd. in the CNA field. The company scored its own bug, picked CWE-121, and pointed the record at its new security-advisories page. That page is also where it says it may keep technical detail fuzzy so the write-up cannot be reused as an exploit guide.
The institutional change is easy to miss beside a QR cartoon. For years Nintendo patched quietly and left the numbering to other CNAs. This record is Nintendo describing a High issue in public, with a CVSS 4.0 vector it chose, on hardware it still sells as a family and still updates. Japanese discussion of the notice kept circling that point: the surprise was not a living-room kart, it was Nintendo putting its own name on the identifier.
The overflow itself is an old class of mistake. A local wireless function copies more data onto the stack than the buffer can hold, and a nearby device that already joined the session can try to steer what runs next. The QR code is only how an outsider gets invited. Nintendo’s first public outing as a CNA is a buffer bug in a pairing path it spent a decade presenting as a simple camera scan.
Unpatched Consoles Still Need a Trip Into System Settings
Anyone still on a system version earlier than 23.0.0 is in the affected set. The practical group is not a random Switch on a shelf. It is a console that still opens Send to Smartphone in a shared space, or a copy of Mario Kart Live that still throws a pairing code onto a TV while a kart hunts for it.
Nintendo’s fallback, if the update cannot be applied right away, is behavioral. Keep those two features in a room where a stranger cannot point a camera at the screen, and do not use someone else’s phone for the Album send.
WHAT NINTENDO TELLS OWNERS TO DO
- The patch: Install system version 23.0.0, which is the build the CVE record treats as the first fixed release.
- The room: If you cannot update yet, only use Send to Smartphone or a Home Circuit kart where nobody else can scan the QR code on the console or the TV.
- The phone: Do not run Send to Smartphone with a smart device that is not yours.
- The other machine: Switch 2 is outside the “obtain console information” impact Nintendo described for this issue, because it does not use that QR hop for Album transfers.
A Switch that never opens those features, and never shows those codes, does not give the attacker the interaction the score expects. A Switch that still does, in an airport lounge or a convention hall or a busy living room, is the machine the notice is for. Firmware 23.0.0 is already out. The remaining risk is the console that has not taken it.
Frequently Asked Questions
How Do I Update a Nintendo Switch to Version 23.0.0?
From the HOME Menu open System Settings, select System, then choose System Update and follow the on-screen prompts until the console reports 23.0.0. The console needs a network connection for that pass, and Nintendo treats this build as the one that removes the overflow from the local wireless path used by the QR features.
How Do I See Which System Version My Switch Is Running?
On the HOME Menu go to System Settings, then System, and read the version string on that screen. Any build numbered below 23.0.0 matches the CVE’s affected range, which the record writes as every Nintendo Switch system version before 23.0.0.
Can This QR Code Bug Be Used Over the Internet?
No. The CVSS vector sets attack access to adjacent network, which means radio range of the console, and Nintendo’s notice still requires a direct scan of the on-screen QR code. Sharing the same home Wi-Fi as the Switch is not enough if the code is never shown, and there is no path in the record for an attacker who only has the owner’s Nintendo Account email.
Do I Need Nintendo Switch Online to Move Switch 2 Screenshots?
No. Switch 2 Album uploads use a free Nintendo Account and the Nintendo Switch App, and Nintendo’s support text says a paid Online subscription is not required. Files stay on Nintendo’s server for 30 days, with a cap of 100 per account, after which older items are removed to make room.
Original Switch consoles that still sit below 23.0.0 will keep drawing those QR codes in Album and in Mario Kart Live. The overflow Nintendo numbered is in the wireless session behind the scan, and that session is what the September 10 update shuts down.
-
TRAVEL3 years agoHow to Get Pre Boarding on Southwest – Skip the Line with These Tricks
-
BUSINESS1 month agoTim Cook’s $4.6 Trillion Apple Still Runs on One Phone
-
ENTERTAINMENT3 weeks agoDunes Air Sues Nora Fatehi Over Its Luxury Jet
-
NEWS3 weeks agoAustralia Treats Cloud Software Payments as Taxable Royalties
-
NEWS3 weeks agoOpenAI Posts a Navier-Stokes Proof Clay Has Not Touched
-
LIFESTYLE3 years agoHow Long Does It Take for Armpit Hair to Grow? The Stages of Hair Growth and How to Shave It
-
NEWS4 weeks agoChina’s Supreme People’s Court Gives AI Apps Safe Harbor
-
LIFESTYLE3 years agoHow Often Do You Have to Change a Monkey’s Diaper? The Truth About Pet Monkeys
