Nintendo has confirmed a security vulnerability in certain QR code functions on the original Nintendo Switch, which could lead to the leakage of console information or the execution of unauthorized code. Affected devices should update their systems to version 23.0.0 as soon as possible.
Documents released by Nintendo on September 10 indicate that the risk involves two usage scenarios: transferring content via the "Send to Smartphone" feature in the Album, and using karts in Mario Kart Live: Home Circuit. Both features display QR codes on the console or TV screen.
This vulnerability requires a malicious third party to directly scan the QR code displayed on the screen to be exploited. If users can prevent others from scanning the QR code during use, the vulnerability will not be exploited; otherwise, attackers may use it to run unauthorized code or access information saved on the console.
The affected devices are original Nintendo Switch consoles with system versions below 23.0.0. Nintendo also stated that there is no risk of console information being accessed on the Nintendo Switch 2.
Users can check their current system version and perform updates by navigating to "System Settings" and then "Console" from the HOME Menu. Users who are temporarily unable to update should ensure that QR codes are not read by third parties when using the aforementioned features, and should not connect any devices other than their own smartphones or karts.

