important · Nintendo Switch Wi-Fi
A nearby attacker can execute arbitrary code on an unpatched Nintendo Switch through local wireless networking.
Affects
Nintendo Switch, Switch Lite, and OLED-model game consoles running Nintendo's embedded system software.
The vulnerable function must be active and its temporary network information exposed; crafted traffic then turns a stack overflow into a ROP chain.
Detail and 2 sources
The resulting execution privilege and directly recoverable console data remain undisclosed.
Chain to watch
Map the vulnerable local-wireless service’s process and privilege context.→↓Determine what console data and persistence become reachable after ROP execution.→↓Nintendo has not disclosed the execution privilege or directly accessible data.
Unverified chainAnalyze the pre-23.0.0 local-wireless service and map the ROP execution context.