Owners of the original Nintendo Switch should patch a newly disclosed security exploit immediately, particularly if they play in public spaces. Nintendo announced the vulnerability on 10 September, shortly after releasing its latest 23.0.0 firmware update.
The exploit applies only to original Nintendo Switch owners using the Send to Smartphone feature. This feature generates a QR code on the Switch that can be scanned with a smartphone, allowing users to transfer game captures and screenshots directly to their phone.
It also affects those playing Super Mario Kart: Home Circuit on the physical cartridge, as the game uses a QR code to establish a wireless link with nearby players.
Should someone else scan the QR code before you, they can connect their device to your Switch and use the connection to run unauthorised code on the console or steal information stored on it. Since your account details are held on the Switch, that is information you would not want falling into someone else’s hands.
The exploit does not affect the Nintendo Switch 2, and people who only play games at home are protected from the issue.
How to fix the problem
The fix is straightforward. Nintendo released update 23.0.0 on 9 September, which resolves the exploit. It is recorded as CVE-2026-82079, described as a stock-based buffer overflow vulnerability that lets attackers within wireless range execute code. It affects only the original Switch on firmware versions older than 23.0.0.
To update your Nintendo Switch, go to System Settings, then System, then System Update to apply the patch. Follow any additional on-screen prompts to complete the installation.
Precautions while you wait
Nintendo says those who cannot update their firmware immediately can avoid the issue by only using the Send to Smartphone feature at home, where attackers cannot see them, or by not playing Super Mario Kart: Home Circuit in public. The company also recommends not scanning any QR codes with a device that is not your own.
The vulnerability affects only the original Switch running firmware versions older than 23.0.0.