Nintendo Switch CVE-2026-82079: A direct QR scan is required
Contents
TL;DR
Impact Nintendo Switch systems before 23.0.0. If a malicious third party directly scans a QR code shown by the affected features, they may be able to execute arbitrary code or access information held by the console. CVSS v4.0: 7.0 (High)
Response Update to system version 23.0.0
Interim Do not let third parties view or directly scan the QR code; use only your own smartphone and kart
On September 10, 2026, Nintendo published an advisory about Nintendo Switch vulnerability CVE-2026-82079. The affected range is system versions before 23.0.0. The attack requires a malicious third party to directly scan a QR code shown on the console or TV by Album’s “Send to Smartphone” or Mario Kart Live: Home Circuit. Nintendo says this could lead to unauthorized code execution or access to information held by the console.
The wireless flaw and affected range
According to the CVE record, the issue is a stack-based buffer overflow in the local wireless networking functionality. Crafted network traffic sent from within wireless range may allow arbitrary code execution. The CVSS v4.0 base score is 7.0, rated High on FIRST’s 0.0–10.0 scale.
The QR code contents and the concrete steps from scanning the code to wireless communication are not disclosed in the public materials. Nintendo notes that information held by Nintendo Switch 2 cannot be obtained through this vulnerability.
Update to 23.0.0 and what to do until then
Nintendo’s system update page lists version 23.0.0 as released on September 10, 2026. From the HOME Menu, open System Settings → System → System Update to check the current version and update.
If you cannot update immediately, do not let third parties view or directly scan the QR codes shown by the two features. Use only your own smartphone for Album’s “Send to Smartphone” and only your own kart in Mario Kart Live: Home Circuit.