r/switch2hacks • u/Prestigious_Fig3645 • Apr 02 '26
r/switch2hacks • u/RojaTop • 25d ago
Hacking Discussion CVE-2025-10263 an exploit that affects ARM Cortex-A78C cores, part of Switch 2's T239 Chip
**TAKE THIS WITH GRAINS OF SALT. NOT GURANTEED HACK FOR SWITCH 2**\*
An exploit in early 2025 was found known as CVE-2025-10263 (ARM Erratum 4193794) was found. It can be used for potential (nothing known yet) Kernel exploit. From the Openwall site (from June 9, 2026) the use of this exploit can be used for escalation:
A malicious guest may be able to write to memory it no longer has permission to write to, after Xen has modified Stage 2 translation to forbid writes to that location. This could allow a guest to escalate its privileges to that of the hypervisor.
A broadcast TLBI on one PE may complete before affected memory accesses on another PE are globally observed. This may permit bypass of Stage 1 translation, Stage 2 translation, or GPT protection.
Now I'm no expert in this field but, we already have userland exploits from Gezine (which avoids the Switch 2 webkit has Arm PAC) and Retroid that start from the unprivileged level. Can that be chained with CVE-2025-10263 for Kernel exploit??
From the RedHat site: This exploit seems to have been fixed, at least on the Linux systems. Even Redhat says it can potentially gain kernel level privilege
This is an Important flaw in the Linux kernel on ARM processors**, allowing a local unprivileged attacker to achieve privilege escalation to kernel level** or a guest virtual machine to escape to the hypervisor.
GBA Temp discussion regarding this said that the exploit was already fixed in the latest 22.5.0 (works until 22.1.0) update. However, it can't be said for certain unless someone in the scene discloses this exploit.
Sources:
https://www.openwall.com/lists/oss-security/2026/06/09/13
https://access.redhat.com/security/cve/cve-2025-10263
r/switch2hacks • u/PandaPandaNoah • Feb 27 '26
Hacking Discussion What is the current status on hacking a switch?
r/switch2hacks • u/FernandoRocker • Oct 01 '25
Hacking Discussion Let me save you the suspense. The Switch 2 won't get hacked.
A little bit of context.
Nintendo actually created a pretty much flawless system with the Switch 1. Read comments by SciresM; the kernel is basically exploit-free.
The Switch 1 is unhackable via software (softmod). The reason why it got hacked was because of NVIDIA, not Nintendo.
An analogy:
Imagine Nintendo creating the most secure safe (safe box) ever. But by a simple rookie mistake, NVIDIA left the keys attached to the safe. That's the reason it was hacked. This is the original paperclip hack.
So Nintendo and NVIDIA removed the key and sealed the keyhole (Mariko revision), but for very technical reasons, they can't change the internals of the safe, only remove the key and seal the keyhole. So, that's why a modchip was created. You are basically opening the sealed keyhole, and reinserting the key. This can't be changed on the original Switch 1.
Switch 1 games are encrypted, and the encryption keys are inside the safe. That's why games can be dumped, but most importantly, decrypted.
Now, for the Switch 2, they keep using the same unhackable software. So, a softmod is highly unlikely. But now NVIDIA created tons of safety measures to avoid the same mistake on the hardware. They basically created a new kind of safe that doesn't use keys anymore (just an analogy), and not only that, but there's no documentation about what they created.
Switch 2 games are encrypted with new encryption methods and keys, and can't be dumped/decrypted until a hack of the Switch 2 happens first. Well, maybe they can be dumped (raw data), but it's useless data without a way to decrypt them.
And sincerely I doubt it will be hacked.
You can find more detailed info here: https://www.reddit.com/r/nintendo/s/BjM0KJt0aw
Outside of very early firmwares, the original Switch doesn’t have any exploitable kernel bugs. There are entry points, but nothing that hands you a full custom firmware. So why does hacking still happen? Because Nvidia screwed up.
Early Switch units became infamous because a simple hardware trick could get you into the device. That “paper-clip” entry point wasn’t some accidental miracle: the Tegra X1 has a recovery mode Nintendo and Nvidia actually use for servicing and flashing. Hackers found two big problems there: recovery mode didn’t check how big a payload was (so it could overflow), and memory wasn’t cleared. Those flaws let attackers run code at the very earliest stage, before Nintendo’s software even starts, and it was devastating. Nintendo fixed it in later chips and changed the USB stack, so that particular exploit (RCM) is a non-starter on newer hardware and won’t be coming back on Switch 2.
The other big class of attacks is voltage glitching. The idea is simple: briefly disturb the CPU’s power so it skips an instruction, and if you hit the right instruction, you can skip crucial checks like signature verification. That’s why early modchips could halt the CPU, inject their own boot code, and then glitch the power at just the right moment to bypass signed checks, essentially re-creating the powerful chain that RCM enabled. With the T239 platform, though, Nvidia and Nintendo put a lot of engineering into stopping both RCM-style problems and glitching.
Software exploits look unlikely, NS2 uses the same kernel and firmware lineage as NS1, and RCM-style bugs aren’t present on T239. Voltage glitching faces two major, practical hurdles. The first is dual-core lockstep: two cores run the same instructions and a comparator checks they match. If one core is fudged, the chip notices and locks down. To beat that you’d need to glitch both cores simultaneously with extreme precision, not easy and not reliable. The second is that the boot/power-management processor is now explicitly untrusted on NS2: anything you could do on that processor won’t let you initialize the rest of the system. You might be able to dump something interesting, but it won’t get you to a usable custom firmware.
That basically leaves two other, much harder targets: NVRISCV (Nvidia’s mostly undocumented security processor) and CCPLEX, the cluster of CPU cores themselves. NVRISCV was designed to resist glitching and to be a sealed black box; attacking it would be like finding a needle in a haystack. CCPLEX attacks would be thwarted in theory by firmware updates and other protections. In short, there’s no obvious silver bullet for NS2, whatever breaks it is likely to be far more sophisticated than what we saw with the 360 hypervisor.
Here is more info: https://blog.ihaveahax.net/2025/06/03/more-details-on-why-the-nintendo-switch-2-may-not-be-hacked/
So, in short. I'm pretty confident on this: the Switch 2 won't get hacked, and you can bookmark this comment and set up a reminder in 5 years or some, return here, and re-read my thread.
r/switch2hacks • u/XxnoubxX • Jun 26 '26
Hacking Discussion remember when people said the switch 2 would be jailbroken immediately?
and people said switch 2 emulation would happen right away? where is it???
didn't have enough money to get the switch 1 v1 at the time had the switch 1 v2 instead. been wanting a modded switch for so long
BUT OF COURSE i get a launch switch 2 day1 and STILL NOTHING its so over
r/switch2hacks • u/BreafingBread • Jul 06 '26
Hacking Discussion We are almost at the same timespan that the Switch was when its bootrom exploit was released to the public (also, RyujinNX was already running games)
So, I thought this was interesting. Saw this thread on GBAtemp comparing the Switch 1 hacking timeline with how it would be on Switch 2. On the thread the OP says that the bootrom was on the wild 396 days after launch, which would be TODAY for switch 2! But I think he got something wrong, because from what I've found, the bootroom exploit was actually 416 days after launch, which would make it July 26th, a few weeks from now. Still, we are on the same month and it just goes to show what a special case Switch 1 hacking was. An updated graph with major milestones would look something like this:
https://i.imgur.com/sjzlRkG.png
However, I'd say tomorrow is also a major milestone, as 397 days after Switch 1 launch is when RyujinNX first booted commercial games (Cave Story and Puyo Puyo Tetris)!
By this point, Switch 1 already had game carts dumped, arbritrary code executed and even emulators (non-functional, but still). Meanwhile, Switch 2 haven't even got game carts dumped a year and a month after launch.
Finally, we are also nearing the first launch of SX OS, which happened 472 days after Switch 1 launch. That would be around September 20th for Switch 2, two months from now.
r/switch2hacks • u/KoopsterShell • Aug 17 '26
Hacking Discussion When will we admit Fernando is right?
More and more time goes on I feel like that guy probably had a point
(CONTEXT: Fernando is the guy in this subreddit that always doomposts in every single post saying the switch 2 is unhackable and will never be hacked. People always meme kn him saying he's just a troll but he probably is right)
r/switch2hacks • u/Ragnatheblooddude • 12d ago
Hacking Discussion Lets say the switch 2 magically got hacked to the point where the switch 1 is now? What could it do? Would it be a vastly superior device to the steam deck?
I guess recently the switch 1 has gotten ALOT of homebrew advancement in the past year with new homebrew ports and stuff. I was kinda inspired to ask because I watched a video where an android tablet from just brute force could run cyberpunk 2077 at 52-55FPS (was the latest legion tablet though). Like can the steam deck even do that with its current hardware? Does the switch 2 have that sorta horsepower where if android was introduced it could run something like cyberpunk with game native at 60+ fps? Like imo at 500 bucks a hacked switch 2 would be an insane device right?
r/switch2hacks • u/UltimateChinaHater • Oct 21 '25
Hacking Discussion So, where are we in the Switch 2 hacking?
I haven't seen any public progress about the switch 2 modding/hacking, did we discover some stuff yet?
r/switch2hacks • u/Final-Tumbleweed-678 • Jul 24 '25
Hacking Discussion Possible new hacking entry-point???
Source:
r/switch2hacks • u/gameplayofdoom • May 24 '26
Hacking Discussion posting ts on my switch 2 (no im not joking look in comments)
r/switch2hacks • u/Creepyhorrorboy • Nov 10 '25
Hacking Discussion Explain it to me like a kid. Why PS5, xbox, PS4 all all having soft modds but switch is getting a hard modd? Is it because of the userbase and the efforts?
I'm really confused about it. I've been trying to get a switch lite modded but people telling to buy a steam deck is double the price. They don't know I'll buy a modded version. Lol. Anyways coming to this doing, why switch getting hardmodd but other consoles are hard to get a hard modd?
r/switch2hacks • u/Gudedomo • 22d ago
Hacking Discussion Missed Day 1 Patch - Now What?
So I bought two Switch 2's at launch and put one away thinking I would save it as a backup or for jailbreak someday. I'm new to the Switch jailbreak scene so I had no idea I needed to do a Day 1 patch. I put the Switch 2 in my closet and kind of forgot about it. Recently started reading about jailbreak requirements and updates only to find out I should have done the Day 1 update. My bad.
Is the only option now to just open it up and update to the current firmware then leaving it offline until a jailbreak comes out? Or is there any other way to invoke the Day 1 patch through a cartridge or something? Sad I waited so long to take it out I know it's my fault for not doing research sooner :( What should I do?
r/switch2hacks • u/auggiethechesscat • Jun 12 '26
Hacking Discussion No, 'there is an exploit, they just aren't disclosing it' is not a smart thing to say.
Firstly, it's an unfalsifiable claim. The exact same logic holds when I say 'there is a teapot orbiting the sun between the Earth and Mars'. There isn't a thing you can do to prove me wrong, so I will claim I'm right. See the issue yet?
If you still don't, the reason it's such a big issue is because there is no conversation that can happen. If we want to talk about X attack vector on the switch 2, we can do so because a. there is more then one answer, and b. everything is can be backed by evidence and reasoning. Neither of those apply for unfalsifiable claims like these.
Secondly, if an exploit exists but no one can know about it, for all intents and purposes, no it doesn't exist. If one person made super awesome emulator that runs everything better then dolphin, but won't tell anyone about it ever, then it effectively doesn't exist. Even if it does, the community gained nothing, and its the exact same as it is without this magical emulator.
The thing that makes an exploit significant is its utility or even just the threat of it's presence. When you take that away and replace it with an empty claim, now its weightless. It means nothing. Sure you have this super awesome kernel vulnerability, but if it can't be explained or demonstrated, let alone used, then its strictly useless. (worse I think)
If you still don't see an issue yet, I can give an example: I can say there is a billion dollars worth of gold under u/beachbali's house, but they won't confirm this, let alone let anyone on to their property to dig or look, but I promise you, its there. They are just waiting for the price of gold to go up before doing anything with it.
This 'conversation' is meaningless. If this is true, it will only matter to anyone when its revealed. That's when the gold is sold and has actual utility. A private exploit doesn't matter until its released.
r/switch2hacks • u/StrangeBaseball5772 • 4d ago
Hacking Discussion Hacking Methods Suggestion
I have been trying a few things and doing some research. Here are my top 3 most likely ideas.
CPU shock at a very specific time and voltage.
The switch 2 uses Webkit 613.0, it has a zero day RCE / Arbitrary code execution. (CVE-2022-32893 and CVE-2022-32863) But then again, why would Nintendo use a bugged Webkit from 2022?
Direct memory access from the SD Express port. This one is kind of a stretch. But I mean, maybe?
r/switch2hacks • u/XTRevivals • Jan 17 '26
Hacking Discussion Things that have happened publicly in the world of Switch 2 hacking (from Discord)
Things that have happened publicly in the world of Switch 2 hacking (as of November 2025)
(CREDITS TO THE SWITCH 2 HACKS DISCORD SEVRER. FORWADED MESSAGE)
tl;dr: Nothing has happened that is of any significance to end-users whatsoever.
- Switch 1 games have been exploited as entry points via transferring malicious saves.
- There are many vulnerable Switch 1 games which can be compromised via a malicious save game. This gives ROP under a switch 1 compatibility process, which is sandboxed and has few interesting privileges.
- This is used as a testbed for research by hackers, but is not presently useful to end-users whatsoever.
- The browser has been compromised on 19.x-20.x.
- By abusing flaws in the web browser, malicious javascript can be served via a captive-portal which compromises the web browser. This gives ROP under the browser, which is sandboxed and has few interesting privileges.
- This is used as a testbed for research by hackers, but is not presently useful to end-users whatsoever.
- This may also work on 21.x, but I believe it is unchecked/untested.
- Ldn sysmodule has been compromised on 19.x-20.x.
- yellows8 found and exploited a bug in the ldn sysmodule, which was fixed in 21.0.0. This is presently not useful to end-users whatsoever.
- sysmodules are compiled with --x (cannot read code from memory) and clangcfi (very difficult/not-known-to-be-possible to subvert control flow).
- This means that sysmodule code cannot be dumped at present even for a compromised module, and custom control flow like ROP cannot be done under sysmodules.
- Thus, sysmodule exploitation is limited to data-only attacks, like e.g. replacing a global handle value in memory so that ldn will transfer it to you.
- Known exploitation result is "access to any service which ldn can access", which again serves as a testbed for research, but is not useful to end-users whatsoever.
- retr0id has explored emfi glitching of the DRAM bus.
- By soldering to the memory bus (e.g. the chip-select line) and attempting to glitch, retr0id has observed that memory operations can be interfered with.
- This can result in e.g. an open-bus like effect, dropped writes, corrupted data reads/etc.
- This is being (very, very slowly) researched by various hackers, but is not presently useful to end-users.
- The primary thing this has taught us is that system memory is encrypted, which makes attacks significantly more difficult to mount.
r/switch2hacks • u/norman157 • Jul 28 '25
Hacking Discussion Hassaku developer bans people after being called out (and it is a virus fyi).
r/switch2hacks • u/Lucaspec72 • Aug 01 '25
Hacking Discussion Actual GBA emulator using the web browser (switch-gba)
Technically this isn't new, or switch 2 specific, but I found this neat little project from 6 years ago made by itsbjoern called switch-gba, it uses the browser to stream a GBA emulator being run on a docker container to the switch. Of course it doesn't run ON the switch 2, and is super limited (no audio, as far as I know, and at least with metroid seems to make me go back to the menu without meaning to (could probably change the mappings to fix that)), but I think it still shows quite well the homebrewing potential of the browser.
Though note again this isn't running anything on the actual switch 2 so it's really just operating as a remote with a screen more than anything else.
oh, and the game shown off is Metroid fusion with the newly released MARS rando.
r/switch2hacks • u/StrangeBaseball5772 • 5d ago
Hacking Discussion eShop URL's
No clue if this can be put here, or if someone already had these. The switch 2 hides the URL's and dosnt announce them passively. So I pointed its DNS to my PC, and was able to log all the URL's the switch 2 uses for the eshop.
connectivity check: ctest.p01.ctest.srv.nintendo.net
penne = account/session service: val/fro-2.p01.lp1.penne.srv.nintendo.net
Nintendo Account login: accounts.nintendo.com
savanna = eShop backend (catalog/purchase/ECS): p01.lp1.savanna.srv.nintendo.net
eShop storefront: beach.p01.lp1.eshop.nintendo.net
They all give the same "Access Denied" when opening from something thats not a Switch. But I thought it might be useful for someone. Its also possible to do this with the other web apps.
r/switch2hacks • u/Big_Week_4790 • 15d ago
Hacking Discussion Banned switch 2 and store
So I got a banned switch 2 that was banned more than a year ago and which I never switched on again.
presently am without another handheld as sold the rog ally x 3 months ago and mainly use my pc.
Dragonwilds is out. Can I still buy it on the banned console and play it with just not be able to play online ?
r/switch2hacks • u/Ill_Ad_7126 • Sep 14 '25
Hacking Discussion Any news on switch 2 hacking?
So it's been kind of a long time since I looked for switch 2 hacking and if I search it up anywhere it gives me old news. Does anyone know what's happening in the switch 2 hacking scene? I really want to know
r/switch2hacks • u/Objective-Top1854 • Dec 23 '25
Hacking Discussion Do you guys think "Softmod" (software unlock) will still come to the Switch V2, Lite, and OLED?
Hey everyone, how's it going? We know that nowadays, for those who have a Switch V2, Lite, or OLED and want to unlock it, the only real option is a modchip (physical installation). But the question remains: do you think that once Nintendo "retires" support for the Switch to focus 100% on its successor, hackers might release some software exploit they've been keeping up their sleeve? Or do you believe that Nvidia's security in these revisions (Mariko/Aula) is so robust that the hardware is truly shielded against software vulnerabilities? I'd like to know your opinion on whether it's worth waiting or if the modchip is the only definitive way forward.
r/switch2hacks • u/StrangeBaseball5772 • 5d ago
Hacking Discussion Mario Kart World URL's
Just posted about the eShop URL's. I now have the ones that Mario Kart World uses. I am thinking about making my PC the kind of "Man in the middle" so i can capture game packets.
Data-store / delivery service: dragons.p01.lp1.dragons.nintendo.net
BCAT background content (news/events feed): topics.p01.lp1.bcat.srv.nintendo.net
Telemetry/play-report ingestion: receive.p01.lp1.dg.srv.nintendo.net
"Tabiji" (journey) service - mid-race, likely stats/records report: api.p01.lp1.tabiji.srv.nintendo.net
r/switch2hacks • u/Intelligent_Mix3971 • Jul 18 '25
Hacking Discussion [DISCUSSION] Factory-test Switch 2 — diagnostic menu enabled, worth modding?
Hey everyone,
I’ve got a brand-new Switch 2 that boots directly into a factory diagnostic screen (options like “reboot,” “aging test,” etc.), not the usual Home UI or recovery mode. It appears unpatched and likely attractive to modders—but I’m curious:
• Has anyone else seen a unit like this? • Does its state matter for current exploits/modchips? • Would this kind of console be more valuable to the community?
I haven’t linked to any sale or included pricing info yet—I’m just looking for feedback and advice on how to proceed properly. Mods, let me know if this belongs in a different thread or a marketplace weekend.
Thanks!
r/switch2hacks • u/Bumoffender • 16d ago
Hacking Discussion Switch 2
I will point you all in right direction efuse start with that you have foundation to bypass stuff later down line on switch 2 .
Sometimes you just need to be pointed on the right direction .