membran  (E-Mail nur eingeloggt Sichtbar) am 12.03.2017 17:05 Uhr
Thema: *knack* Antwort auf: Nintendo Schalter - Der letzte switcht das Licht aus! von Felix Deutschland
Schwachstelle: Der versteckte Browser. Noch ist nichts released und Nintendo dürfte Firmwareupgrades machen, aber diese Firmwareversion scheint verwundbar. Ganz offen scheint es auch noch nicht zu sein.

[http://neogaf.com/showthread.php?t=1351906]

It appears that the not-so-well hidden Nintendo Switch browser shipped with a bunch of old vulnerabilities that hackers were able to leverage. Yesterday, hacker qwertyoruiop (known for Jailbreaks of multiple iOS versions, and who also contributed to the PS4 1.76 Jailbreak) posted a screenshot of what seems to be a Webkit exploit running on the Nintendo Switch.

Nintendo Switch hack leverages known webkit vulnerability
According to the hacker, “all” he had to do was slightly tweak his existing jailbreakMe iOS Webkit exploit (hence the mention of iOS and pangu in the screenshot) and remove iOS specific code from it. Although qwertyoruiop has not provided any proof or release besides a screenshot, the hacker’s reputation makes it highly unlikely to be a hoax (I do not have access to the hack or a Nintendo Switch here to verify. It might actually be the first time in history that people could get their hands on a console hack more easily than on the console itself).


For now, this hack doesn’t mean much for the end user: nothing’s been released yet, and this is only a userland eploit. Although it might allow running unsigned code, hackers are typically after a bigger prey: Kernel access. I wouldn’t be surprised if nothing was released until hackers get a better understanding of the console’s internals, and potentially find privilege escalation vulnerabilities (kernel exploits).

But since the vulnerability is apparently public, it is very likely that Nintendo will quickly release a firmware update with a patch for the Switch. As always, people looking to hack their console will want to wait patiently on a low firmware.
< Auf diese Nachricht antworten >