Nintendo released Nintendo Switch firmware 23.0.0 on Sept. 9, 2026, then followed it a day later with a security advisory warning that original Switch consoles running any earlier firmware version are exposed to a proximity-based attack. The flaw lets someone within wireless range hijack QR-code-based features to run unauthorized code or pull information stored on the console, according to Nintendo’s advisory as reported by CNET. The Nintendo Switch 2 is not affected.
Here’s the context: the exposure comes down to two features that generate scannable QR codes. The original Switch’s Send to Smartphone tool creates a code you scan to pull screenshots and video captures onto your phone, and the physical cartridge version of Super Mario Kart: Home Circuit uses a QR code to pair with nearby players. If someone else scans that code before you do, they can connect their own device to your console through that link – and since account information lives on the Switch itself, that’s the data actually at risk.
The practical upshot is that this is a public-space problem more than a living-room one. Nintendo’s own guidance, per the advisory, is that people who only use these features at home aren’t exposed to this particular attack, since it requires a third party to physically scan the code as it’s displayed. That’s also the same reasoning behind other recent Switch access hiccups worth knowing about, including our look at a separate Switch 2 service-access issue that left some players locked out.
The fix and the interim precautions are straightforward:
- Update path – Go to System Settings > System > System Update on your console and install firmware 23.0.0 or later.
- Who’s affected – Only original Nintendo Switch consoles running firmware older than version 23.0.0.
- Send to Smartphone – Until you update, use this feature only at home where no one else can scan the code.
- Mario Kart Live: Home Circuit – Avoid playing the physical cartridge version in public until your firmware is current.
- QR codes generally – Don’t scan a code with any device that isn’t your own.
- Tracking number – Nintendo has catalogued the issue as CVE-2026-82079, described in the advisory as a stack-based buffer overflow.
For anyone who can’t update immediately, Nintendo’s fallback guidance is the same set of precautions above rather than a separate workaround. If you’re still deciding how much of your Switch library and account activity runs through Nintendo’s connected services, it’s worth revisiting what Nintendo Switch Online actually covers before you decide how urgently to patch. Have you already installed firmware 23.0.0 on your original Switch, and does this change how you’ll use Send to Smartphone in public?





















