libwebp vulnerability - does it exist in the Switch and can it be exploited?

Arumaruma

New Member
OP
Newbie
Joined
Sep 27, 2023
Messages
1
Trophies
0
Age
25
XP
22
Country
United Kingdom
So a critical vulnerability in a library called libwebp has appeared. Seems like a pretty big deal. It's already fixed in major browsers but the Switch hasn't had an update yet since it was found. I wonder if it can be played around with in the Switch browser?
 

SylverReZ

Dat one with the Rez
Member
GBAtemp Patron
Joined
Sep 13, 2022
Messages
7,178
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
22,025
Country
United Kingdom
So a critical vulnerability in a library called libwebp has appeared. Seems like a pretty big deal. It's already fixed in major browsers but the Switch hasn't had an update yet since it was found. I wonder if it can be played around with in the Switch browser?
This is a very interesting discovery, similar to browserhax on the 3DS. Perhaps another softmod for the Switch without RCM?
 
  • Like
Reactions: jeffyTheHomebrewer

PTwr

Member
Newcomer
Joined
Dec 5, 2013
Messages
9
Trophies
0
Age
55
XP
102
Country
Afghanistan
You might be onto something! Maybe through some DNS server we could redirect the switch's browser applet to a custom website/page with a malformed webp image and use that to somehow get CFW running?
There is DNS hack to open built-in crappy browser on Switch, but its some half useless obsolete crap.
 

E1ite007

wierd avatar guy
Member
Joined
Nov 19, 2016
Messages
1,033
Trophies
1
Location
Itchy & Scratchy Land
XP
2,747
Country
Mexico
Considering it causes a heap-based buffer overflow, yes it could be posible to load unauthorized code, but I doubt it would work by itself since it would load on Horzion OS, where most piracy protections are already loaded and working. It would need a way to bypass all the security measures after a reboot to enable homebrew and piracy.

It could be the begining of something.
 
  • Like
Reactions: jeffyTheHomebrewer

masagrator

The patches guy
Developer
Joined
Oct 14, 2018
Messages
6,280
Trophies
3
XP
12,047
Country
Poland
Buffer overflow in Switch browser will cause crash. Simple as that.

You cannot execute code in HOS without setting used memory region as executable. And to do that it requires certain permissions that Switch's web browser doesn't have since Pegascape was patched.

So maybe someone will discover new softmod, but it won't work on newer FWs than PegaScape already supports.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,323
Trophies
2
XP
18,178
Country
Sweden
Buffer overflow in Switch browser will cause crash. Simple as that.

You cannot execute code in HOS without setting used memory region as executable. And to do that it requires certain permissions that Switch's web browser doesn't have since Pegascape was patched.

So maybe someone will discover new softmod, but it won't work on newer FWs than PegaScape already supports.
They really learned. I don't dare to think how the next Switch will ne
 

Morricorne

Well-Known Member
Member
Joined
Jun 14, 2019
Messages
295
Trophies
0
Age
32
Location
Łódź
XP
846
Country
Poland
They hack Switch with browser exploit sooner or later. But i think after new Nintendo console release. Nobody risk show new exploit. When Nintendo is still closely watching switch homebrew scene.
 

RednaxelaNnamtra

Well-Known Member
Member
Joined
Dec 8, 2011
Messages
1,208
Trophies
1
XP
3,343
Country
Germany
They hack Switch with browser exploit sooner or later. But i think after new Nintendo console release. Nobody risk show new exploit. When Nintendo is still closely watching switch homebrew scene.
The main problem is not the entry point though, the main problem is the kernel or trustzone, which both don't seem to contain any exploitable flaws.
Keep in mind that those two are the main parts of the os we want for CFW, without them not CFW.
Those two parts are also very small code wise, and only do what they need to, which makes it actually possible for developers to actually know all the code and keep it secure.
So unless by some miracle nintendo adds a big bug in a future version, its unlikely we will get anywhere, even if we find a browser exploit as entry point to trigger other exploits and get more access. So software only exploits are unlikely.
But yeah, even if someone found something, it would be much smarter to wait for the follow up console to have a starting point there.
 
  • Like
Reactions: Morricorne

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    BunnyPinkie @ BunnyPinkie: Currently asked for mecha mote iinchou mm my best friend to be translated but I also want to ask...