Nintendo today issued a new security advisory, disclosing a security vulnerability affecting Switch consoles. This vulnerability could allow third parties to run unauthorized code on user consoles or access some of the information stored on them via close-range remote attacks.
According to Nintendo, the attack method is relatively limited. Malicious third parties must directly scan the QR code displayed on the Switch console screen (or TV screen), and the QR code must appear in one of the following two scenarios: when using the "Send to Smartphone" feature in the Album, or when playing Mario Kart Live: Home Circuit with a kart.
If the QR code is not scanned, users will not be affected. Once the QR code is scanned, others may be able to run unauthorized code on the user's Switch console or access information stored on the console.
Nintendo has confirmed that the affected devices are Switch consoles with system firmware versions lower than 23.0.0. Additionally, this vulnerability cannot be used to obtain information from the Nintendo Switch 2.
Nintendo has proposed the following preventive measures in its announcement:
First, update your console to the latest system version (23.0.0). Users can check their current system version by selecting "System Settings" > "System" from the HOME Menu, where they can also perform updates.
If you cannot update to the latest version immediately, Nintendo recommends that users pay attention to the following points:
When using the "Send to Smartphone" feature in the Album, or when playing Mario Kart Live: Home Circuit with a kart, ensure that third parties cannot scan the QR code displayed on the console screen (or TV screen) in your environment.
Furthermore, when using the "Send to Smartphone" feature in the Album, avoid using smartphones that do not belong to you; similarly, when playing Mario Kart Live: Home Circuit, avoid using karts that do not belong to you.
Nintendo previously released a major update, version 23.0.0, for the Nintendo Switch 2, adding several new features.

