Junglewise Threat Intelligence

CVE-2026-82079: Nintendo Switch stack-based buffer overflow in wireless networking

CVE-2026-82079 · Severity: high · CVSS 8.4 · Published 2026-09-10

Executive brief

The Nintendo Switch game console contains a vulnerability in its local wireless networking subsystem that could allow an attacker within wireless range to execute arbitrary code on the device. An attacker could exploit this to gain complete control of the console, potentially accessing saved games, account data, and installed software.

Technical details

A stack-based buffer overflow exists in the Nintendo Switch local wireless networking functionality. The vulnerability allows an attacker within wireless range to transmit crafted network traffic that overflows a stack buffer, enabling return-oriented programming (ROP) attacks to achieve arbitrary code execution. No user interaction is required; the attacker only needs to be within wireless range of the device. The vulnerability affects Nintendo Switch systems running firmware versions before 23.0.0. Nintendo has released a security update to address this issue.

Affected products

  • Nintendo Switch before 23.0.0

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: Security update version 23.0.0 available

References