A new exploit has been found for Nintendo Switch 2, working without internet or system updates

20 Jul 18:53

However, this is not yet a full console hack.

Developer under the pseudonym Gezine reported that they managed to discover a new user exploit compatible with both the original Nintendo Switch and the Nintendo Switch 2.

According to them, the new method fundamentally differs from existing ways of running user code. While previous exploits mainly relied on modified saves or WebKit vulnerabilities, the new development does not use either of these approaches.

The main advantage of the new exploit is that it works completely offline. Existing methods usually require transferring special save files via the Nintendo Switch Online service, which forces console owners to update to the current firmware version, where the necessary vulnerabilities may already be patched. Gezine's solution eliminates this dependency and, it is claimed, is compatible with all versions of the system software.

The development gains additional value from the fact that Nintendo has significantly strengthened the protection of Switch 2. In particular, the WebKit browser engine received the ARM PAC (Pointer Authentication Code) mechanism, which complicates the exploitation of such vulnerabilities. The new exploit does not depend on WebKit, thereby bypassing one of the key limitations of modern methods.

However, this is not yet a full hack of the Nintendo Switch 2. The new exploit only provides user-level access, which is not enough for full control over the system. Nevertheless, for the homebrew development community, this could be an important starting point. In the future, such access could open up the possibility for creating save backup utilities, running retro console emulators, and other unofficial software.