Nintendo warns Switch QR code exploit could hack console and issues firmware update
Key Points:
- Nintendo has released firmware version 23.0.0 for the Switch to fix a "proximity-based remote attack" vulnerability involving QR codes generated by the Album feature and Mario Kart Live: Home Circuit.
- The security flaw, identified as CVE-2026-82079, could allow hackers to run unauthorized code or steal data by exploiting QR codes used to transfer screenshots or connect karts wirelessly.
- Nintendo warns users without internet access who cannot update their consoles to avoid sharing Album media or linking Mario Kart karts with strangers to reduce risk.
- The upcoming Switch 2 console is not affected by this vulnerability and benefits from new features in the 23.0.0 update, including the ability to share Miis via QR codes.
- The update also improves docked mode on the Switch 2 by adding VRR (Variable Refresh Rate) support, reducing stuttering during gameplay on compatible TVs.